S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 8, 2025

CVE-2023-3388 Scanner

CVE-2023-3388 Scanner - Cross-Site Scripting vulnerability in Beautiful Cookie Consent Banner

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-3388
6.1
CVSShigh
Exploitable remotely over the internet · no authentication required.

The Beautiful Cookie Consent Banner for WordPress is vulnerable to Stored Cross-Site Scripting via the 'nsc_bar_content_href' parameter in versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A partial patch was made available in 2.10.1 and the issue was fully patched in 2.10.2.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Beautiful Cookie Consent Bannerby nikelschubert
0
Updated Aug 22, 2026View on NVD →
Detail

The Beautiful Cookie Consent Banner is a WordPress plugin used to provide cookie consent options on websites. Website administrators utilize it to ensure compliance with cookie consent laws across various regions. The plugin is popular among users who want to display customizable cookie banners to visitors. It allows users to easily integrate and manage cookie consent notices on their websites. The plugin is designed to be user-friendly and efficient, making it an essential tool for website compliance. However, due to its widespread use, it can become a target for potential security vulnerabilities.

Cross-Site Scripting (XSS) is a vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. In the case of the Beautiful Cookie Consent Banner, this vulnerability is present due to insufficient input sanitization and output escaping. The specific vulnerability allows unauthenticated attackers to exploit the 'nsc_bar_content_href' parameter. As a result, arbitrary scripts can be executed in the browsers of users accessing an affected page. This type of vulnerability can lead to severe user impact, including data theft and compromised user sessions.

The technical details of the vulnerability involve the misuse of the 'nsc_bar_content_href' parameter within the Beautiful Cookie Consent Banner. By failing to properly sanitize user inputs, attackers can craft requests that inject malicious scripts. These scripts execute in the context of the victim's browser during interaction with an impacted page. The vulnerability existed in plugin versions up to 2.10.1. The issue was acknowledged, and a partial patch was introduced in version 2.10.1, with a complete fix available in version 2.10.2. Affected sites should upgrade to a patched version to eliminate the vulnerability.

Exploiting this vulnerability could allow attackers to perform a range of malicious activities. Possible effects include session hijacking, defacement of website content, or redirection of users to malicious sites. Attackers could also gain unauthorized access to sensitive user data or alter the behavior of the targeted website. Users might experience unexpected behavior when interacting with compromised elements of the site. Such exploitation underscores the importance of prompt patching and securing of plugins used in web applications.

REFERENCES

Solution Advice
  • Upgrade to Beautiful Cookie Consent Banner version 2.10.2 or later to ensure the vulnerability is fully patched.
  • Regularly review and update WordPress plugins and themes to the latest versions to protect against known vulnerabilities.
  • Implement security measures such as web application firewalls to monitor and block malicious requests.
  • Ensure all user inputs are sanitized and validated to prevent injection attacks across your web applications.
  • Conduct periodic security audits on your WordPress setup to identify potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.