PT-2021-15938 · WordPress · Easy Cookies Policy
0Xb9
·
Published
2021-07-06
·
Updated
2022-07-28
·
CVE-2021-24405
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Easy Cookies Policy WordPress plugin versions 1.6.2 and earlier
Description
The issue allows any authenticated users, such as subscribers, to change settings due to a lack of capability and CSRF checks. This can also be exploited through CSRF if user registration is not possible. Additionally, the cookie banner setting is not properly sanitized or validated before being output on all frontend and backend pages, leading to a Stored Cross-Site Scripting issue.
Recommendations
For versions 1.6.2 and earlier, update to a version that includes the necessary capability and CSRF checks for saving settings, and ensure proper sanitization and validation of the cookie banner setting to prevent Stored Cross-Site Scripting.
As a temporary workaround, consider restricting access to the settings page to prevent unauthorized changes until a patch is available.
Avoid using the vulnerable cookie banner setting in the affected API endpoints until the issue is resolved.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easy Cookies Policy