Vulnerability record · CVE-2023-3388 · published 24 June 2023
CVE-2023-3388: WordPress Beautiful Cookie Consent Banner stored XSS via href parameter
Beautiful Cookie Banner · Beautiful Cookie Consent Banner
The Beautiful Cookie Consent Banner plugin for WordPress fails to sanitize and escape the 'nsc_bar_content_href' parameter, allowing stored cross-site scripting in versions up to and including 2.10.1. Injected scripts persist in pages and execute for any visitor, so the flaw matters for any site running the affected plugin. A partial fix landed in 2.10.1 and a full fix in 2.10.2.
Description
The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A partial patch was made available in 2.10.1 and the issue was fully patched in 2.10.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe flaw is remotely reachable, has a full patch available, and shows very high EPSS with a referenced large-scale exploitation campaign despite no KEV listing.
What it is
The Beautiful Cookie Consent Banner plugin for WordPress fails to sanitize and escape the 'nsc_bar_content_href' parameter, allowing stored cross-site scripting in versions up to and including 2.10.1. Injected scripts persist in pages and execute for any visitor, so the flaw matters for any site running the affected plugin. A partial fix landed in 2.10.1 and a full fix in 2.10.2.
Impact
An attacker can run arbitrary JavaScript in the browser of any user viewing an injected page, enabling session theft, credential phishing, or page defacement in the context of the vulnerable site.
Attack surface
Reachable over the network through the plugin's cookie banner content parameter; the CVSS vector shows no privileges required but user interaction is required for the payload to execute in a victim's browser.
Exploitation
Not listed in CISA KEV, but EPSS is very high at 0.843 (99.7th percentile), and a third-party advisory references a large-scale XSS campaign, indicating active exploitation in the wild.
What to do
- Update Beautiful Cookie Consent Banner to 2.10.2 or later immediately.
- If patching is not possible, disable or remove the plugin until it can be updated.
- Deploy a WAF rule blocking script injection through the nsc_bar_content_href parameter.
- Audit stored banner content and database rows for injected script payloads and clean them.
- Restrict or monitor who can modify cookie banner settings.
Detection
- Search the WordPress database and plugin settings for script tags or event handlers in nsc_bar_content_href values.
- Monitor web logs and WAF alerts for requests containing script payloads targeting the cookie banner parameter.
- Review pages rendering the cookie banner for unexpected inline JavaScript or external script loads.
- Check for unusual admin or session activity on sites running the affected plugin.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-3388 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-3388), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.