Cyber Posture

CVE-2025-23501

High

Published: 16 January 2025

Published
16 January 2025
Modified
23 April 2026
KEV Added
Patch
CVSS Score 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Score 0.0014 33.4th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Description

Cross-Site Request Forgery (CSRF) vulnerability in SpruceJoy Cookie Consent & Autoblock for GDPR/CCPA cookie-consent-autoblock allows Stored XSS.This issue affects Cookie Consent & Autoblock for GDPR/CCPA: from n/a through <= 1.0.1.

Security Summary

CVE-2025-23501 is a Cross-Site Request Forgery (CSRF) vulnerability in the SpruceJoy Cookie Consent & Autoblock for GDPR/CCPA WordPress plugin (cookie-consent-autoblock). The flaw allows for Stored Cross-Site Scripting (XSS) and affects all versions up to and including 1.0.1. It carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L) and maps to CWE-352.

Unauthenticated attackers can exploit this over the network with low attack complexity, though it requires user interaction. By tricking a site administrator or other privileged user into visiting a malicious webpage, an attacker can forge a request to perform an administrative action that injects and stores a malicious XSS payload. The stored script then executes in the context of the site's scope for subsequent visitors, enabling limited impacts such as low confidentiality, integrity, and availability violations, including potential session hijacking or data theft.

Advisories, including the Patchstack database entry at https://patchstack.com/database/Wordpress/Plugin/cookie-consent-autoblock/vulnerability/wordpress-cookie-consent-autoblock-for-gdpr-ccpa-plugin-1-0-1-csrf-to-stored-cross-site-scripting-xss-vulnerability?_s_id=cve, provide further details on the vulnerability. Security practitioners should review these for recommended mitigations, such as updating the plugin or implementing CSRF protections.

Details

CWE(s)
CWE-352

References