CVE-2025-49428 HIGH

CVE-2025-49428: WordPress Cookie Warning plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability

Vendor Dourou
Product Cookie Warning
Weakness CWE-79 · XSS
Published August 20, 2025
Last update April 28, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dourou Cookie Warning allows Stored XSS. This issue affects Cookie Warning: from n/a through 1.3.

Explanation of Vulnerability in Simple Terms

02Summary

Cookie Warning versions up to 1.3 contain a cross-site scripting (XSS) vulnerability that allows authenticated users with low privileges to inject malicious scripts. An attacker can craft input that executes in other users' browsers, potentially stealing session data or performing actions on their behalf. The vulnerability requires network access and some attack complexity but can compromise site confidentiality, integrity, and availability.

What an attacker can do

03Attacker Capabilities

Inject and execute malicious JavaScript in other users' browsers to steal data or perform unauthorized actions.

Potential impact on your site

04Site Impact

Authenticated users can inject scripts affecting other visitors; attackers may steal admin sessions or modify site content.

Conditions required to exploit

05Prerequisites

Attacker must have low-level authenticated access to the site; no user interaction required from victims.

Key dates

06Disclosure timeline

August 20, 2025 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE