Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24595

Опубликовано: 18 окт. 2021
Источник: nvd
CVSS3: 6.5
CVSS2: 4.3
EPSS Низкий

Описание

The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a CSRF attack.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wp_cookie_choice_project:wp_cookie_choice:*:*:*:*:*:wordpress:*:*
Версия до 1.1.0 (включая)

EPSS

Процентиль: 36%
0.00154
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

The Wp Cookie Choice WordPress plugin through 1.1.0 is lacking any CSRF check when saving its options, and do not escape them when outputting them in attributes. As a result, an attacker could make a logged in admin change them to arbitrary values including XSS payloads via a CSRF attack.

EPSS

Процентиль: 36%
0.00154
Низкий

6.5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79
CWE-79