CVE WATCH / VULNERABILITY DETAIL
CVE-2026-92977
HIGHCVSS 7.2NVD feed
Published 3 October 2026 · tracked since 3 October 2026
Description
The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-105146 MEDIUM 4.7
- CVE-2026-105144 MEDIUM 5.3
- CVE-2026-105137 MEDIUM 5
- CVE-2026-86817
- CVE-2026-93549
- CVE-2026-97332
- CVE-2026-17005
- CVE-2026-104119
- CVE-2026-104118
- CVE-2026-105123 HIGH 8.8