Vulnerability Details CVE-2021-24595
The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a CSRF attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.7%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.3
Products affected by CVE-2021-24595
-
cpe:2.3:a:wp_cookie_choice_project:wp_cookie_choice:-
-
cpe:2.3:a:wp_cookie_choice_project:wp_cookie_choice:1.1.0