vendor:
Easy Cookie Policy
by:
0xB9
6.5
CVSS
MEDIUM
Broken Access Control
287
CWE
Product Name: Easy Cookie Policy
Affected Version From: 1.6.2002
Affected Version To: 1.6.2002
Patch Exists: YES
Related CWE: CVE-2021-24405
CPE: a:wordpress:easy_cookies_policy:1.6.2
Platforms Tested: Windows 10
2021
WordPress Plugin Easy Cookie Policy 1.6.2 – Broken Access Control to Stored XSS
Broken access control allows any authenticated user to change the cookie banner through a POST request to admin-ajax.php. If users can't register, this can be done through CSRF.
Mitigation:
Upgrade to version 1.6.3 or later.