Google Analytics Counter Tracker <= 3.4.1 - Unauthenticated PHP Object Injection
criticalThe Google Analytics Counter Tracker plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.4.1 via deserialization of untrusted input from the vulnerable wpadm_ga_request cookie parameter. This allows unauthenticated attackers to inject a PHP Object.
- CVSS:
- 9.8
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.0
- Disclosed:
- Dec 11, 2016