CVE-2021-24405

MEDIUM

easy_cookies_policy < 1.6.2 - Authenticated Stored Cross-Site Scripting via Settings Update

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-24405. PoCs published by 0xB9.

AI-analyzed exploit summary This exploit demonstrates a broken access control vulnerability in WordPress Plugin Easy Cookie Policy 1.6.2, allowing any authenticated user to inject malicious scripts via a POST request to admin-ajax.php. The PoC includes a simple XSS payload to prove the vulnerability.

Description

The Easy Cookies Policy WordPress plugin through 1.6.2 is lacking any capability and CSRF check when saving its settings, allowing any authenticated users (such as subscriber) to change them. If users can't register, this can be done through CSRF. Furthermore, the cookie banner setting is not sanitised or validated before being output in all pages of the frontend and the backend settings one, leading to a Stored Cross-Site Scripting issue.

Exploits (1)

exploitdb WORKING POC
by 0xB9 · textwebappsphp
https://www.exploit-db.com/exploits/50849

This exploit demonstrates a broken access control vulnerability in WordPress Plugin Easy Cookie Policy 1.6.2, allowing any authenticated user to inject malicious scripts via a POST request to admin-ajax.php. The PoC includes a simple XSS payload to prove the vulnerability.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin Easy Cookie Policy 1.6.2
Auth required
Prerequisites: Authenticated user access to WordPress · WordPress Plugin Easy Cookie Policy 1.6.2 installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://wpscan.com/vulnerability/9157d6d2-4bda-4fcd-8192-363a63a51ff5

Scores

CVSS v3 6.5
EPSS 0.1099
EPSS Percentile 95.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-863
Status published
Products (1)
izsoft/easy_cookies_policy < 1.6.2
Published Jul 06, 2021
Tracked Since Feb 18, 2026