PT-2026-43539 · Rahulbhangale+1 · Wp Promoter
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Promoter versions prior to 1.4
Description
Unauthorized modification of data is possible due to a missing capability check in the
reset stats() function. This function is linked to the wp ajax wpp-reset stats and wp ajax nopriv wpp-reset stats API endpoints and lacks authentication, authorization, or nonce validation. Consequently, unauthenticated attackers can reset bar and popup statistics by deleting the wpp bar and wpp popup options.Recommendations
Update WP Promoter to version 1.4 or later.
As a temporary mitigation, restrict access to the
wp ajax wpp-reset stats and wp ajax nopriv wpp-reset stats endpoints.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Promoter