Cookie Params <= 0.2 - Reflected Cross-Site Scripting and Cross-Site Request Forgery
mediumThe Cookie Params plugin for WordPress is vulnerable to Reflected Cross-Site Scripting and Cross-Site Request Forgery due to missing sanitization and nonce protection on the debug() and options_page() function in versions up to, and including, 0.2.
- CVSS:
- 6.1
- Affected:
- up to 0.2
- Fix:
- No patched version reported
- Disclosed:
- May 31, 2022