VYPR
Medium severity5.9NVD Advisory· Published Dec 9, 2025· Updated Apr 15, 2026

CVE-2025-67554

CVE-2025-67554

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Humanityco Cookie Notice & Compliance for GDPR / CCPA cookie-notice allows Stored XSS.This issue affects Cookie Notice & Compliance for GDPR / CCPA: from n/a through <= 2.5.8.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS vulnerability in Cookie Notice & Compliance for GDPR/CCPA plugin (<=2.5.8) allows attackers to inject malicious scripts via improper input neutralization.

Overview

A stored cross-site scripting (XSS) vulnerability exists in the Cookie Notice & Compliance for GDPR / CCPA WordPress plugin (versions up to and including 2.5.8). The flaw arises from improper neutralization of user input during web page generation, allowing malicious JavaScript to be stored and executed in the context of an administrator's session [1].

Exploitation

Requirements Exploitation requires a user with administrative privileges to perform an action such as clicking a crafted link or submitting a form, meaning the attacker must first convince a privileged user to trigger the payload. Once activated, the injected script is saved and will execute for other visitors [1].

Impact

Successful exploitation could allow attackers to inject arbitrary scripts, including redirects, advertisements, or other HTML payloads, potentially compromising site integrity and user sessions [1].

Mitigation

The developer has patched this vulnerability in version 2.5.9. Users are strongly advised to update immediately. For those unable to update, contacting the hosting provider or web developer for assistance is recommended [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.