Wp Cookie Choice [wp-cookiechoise] <= 1.1.0 (unfixed + closed)
unknown
[en] The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a CSRF attack.
- Affected:
- up to 1.1.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 18, 2021
CVE-2021-24595 on NVD →
Wp Cookie Choice <= 1.1.0 - Cross-Site Request Forgery to Cross-Site Scripting
medium
The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a CSRF attack.
- CVSS:
- 6.5
- Affected:
- up to 1.1.0
- Fix:
- No patched version reported
- Disclosed:
- Sep 20, 2021
CVE-2021-24595 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database