PT-2026-44178 · Bensibley+1 · Independent Analytics – Wordpress Analytics Plugin+1
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Independent Analytics versions prior to 2.15.0
Description
An unauthenticated attacker can perform Server-Side Request Forgery (SSRF) by injecting malicious domains into the database. This is possible through the '/wp-json/iawp/search' endpoint, which accepts attacker-controlled
referrer url values. The issue stems from insufficient signature validation, as the signature is embedded in public JavaScript and uses a static salt per site. Additionally, a scheduled favicon fetcher uses raw cURL functions without protection mechanisms, such as localhost blocking or private network filtering, and fails to use the wp safe remote * functions. This allows the trigger of server-side requests to arbitrary hosts, including internal services.Recommendations
Update Independent Analytics to version 2.15.0 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Independent Analytics – Wordpress Analytics Plugin
Independent-Analytics