plugin

Easy Cookies Policy Vulnerabilities

1 known security issue reported for the Easy Cookies Policy WordPress plugin. Most recent disclosed Jun 11, 2021.

1 medium

Running Easy Cookies Policy on your site? Check whether your installed version is affected.

Scan your site free

Easy Cookies Policy <= 1.6.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting

medium

The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them. If users can't register, this can be done through CSRF. Furthermore, the cookie banner setting is not sanitised or validated bef...

CVSS:
6.4
Affected:
up to 1.6.2
Fix:
No patched version reported
Disclosed:
Jun 11, 2021

CVE-2021-24405 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database