Wp Cookie Choice <= 1.1.0 - Cross-Site Request Forgery to Cross-Site Scripting

2021-09-20 00:00
dc11

Strategic Overview

Status
Unpatched
Affected PluginWp Cookie Choice
Affected Version<= 1.1.0
CVSS6.5Medium
CVECVE-2021-24595
View all Wp Cookie Choice vulnerabilities

Vulnerability Overview

The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a CSRF attack.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C