→ برگشت به فید آسیبپذیریها
CVE-2026-14989 · gdpr-cookie-consent
اسکریپتنویسی ذخیرهشده (Stored XSS) در افزونه Cookie Banner for GDPR / CCPA
افزونه Cookie Banner for GDPR / CCPA وردپرس در نسخههای تا ۴.۴.۱ به دلیل sanitization ناکافی ورودی و escaping خروجی، از طریق پارامتر wpl_user_preference در برابر حمله Stored XSS آسیبپذیر است. مهاجمان بدون احراز هویت میتوانند اسکریپتهای مخرب تزریق کنند که هنگام بازدید کاربران از صفحه آلوده اجرا میشود. نقطه پایانی AJAX ثبت رضایت عمومی بوده و nonce آن در فرانتاند در دسترس است؛ بهروزرسانی فوری افزونه اکیداً توصیه میشود.
نسخههای تحت تأثیر
<= 4.4.1
راهنمای اقدام و رفع مشکل (Remediation)
- ۱. پشتیبانگیری: قبل از اعمال هرگونه تغییر، یک بکاپ کامل از پایگاه داده و فایلهای سایت تهیه کنید.
- ۲. بهروزرسانی سریع: افزونه یا هسته gdpr-cookie-consent را بلافاصله به آخرین نسخه ارائهشده ارتقا دهید.
- ۳. فایروال و مانیتورینگ: در صورت عدم امکان آپدیت فوری، رولهای امنیتی WAF را فعال کرده و لاگهای وبسرور را پایش نمایید.
مراجع رسمی و مستندات
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6045c4fd-60ed-4771-93f4-d4df41ef888b?source=api-prod ↗
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6045c4fd-60ed-4771-93f4-d4df41ef888b ↗
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.2.7/public/modules/consent-logs/class-wpl-consent-logs.php#L700 ↗
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.2.7/public/modules/consent-logs/class-wpl-cookie-consent-consent-logs.php#L594 ↗
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.2.7/public/modules/consent-logs/class-wpl-cookie-consent-consent-logs.php#L725 ↗
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/public/modules/consent-logs/class-wpl-consent-logs.php#L700 ↗
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/public/modules/consent-logs/class-wpl-cookie-consent-consent-logs.php#L594 ↗
- https://plugins.trac.wordpress.org/browser/gdpr-cookie-consent/tags/4.3.5/public/modules/consent-logs/class-wpl-cookie-consent-consent-logs.php#L725 ↗
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3674117%40gdpr-cookie-consent&new=3674117%40gdpr-cookie-consent ↗
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6045c4fd-60ed-4771-93f4-d4df41ef888b?source=cve ↗