PT-2026-43537 · Rchmura+1 · Gostats For Wordpress
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GoStats for WordPress versions prior to 1.5
Description
Cross-Site Request Forgery occurs due to missing or incorrect nonce validation in the
gostats manage() function. This allows unauthenticated attackers to update plugin settings, specifically the gostats siteid and gostats server options, by tricking a site administrator into clicking a malicious link.Recommendations
Update GoStats for WordPress to version 1.5 or later.
As a temporary mitigation, restrict administrative access to the plugin management interface.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gostats For Wordpress