Wordpress plugin easy cookie policy 1.6.2 broken access control to stored xss Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2022-03-30 |
Type : webapps |
Platform : php
This exploit / vulnerability Wordpress plugin easy cookie policy 1.6.2 broken access control to stored xss is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
# Exploit Title: WordPress Plugin Easy Cookie Policy 1.6.2 - Broken Access Control to Stored XSS
# Date: 2/27/2021
# Author: 0xB9
# Software Link: https://wordpress.org/plugins/easy-cookies-policy/
# Version: 1.6.2
# Tested on: Windows 10
# CVE: CVE-2021-24405
1. Description:
Broken access control allows any authenticated user to change the cookie banner through a POST request to admin-ajax.php.
If users can't register, this can be done through CSRF.