Easy Google Analytics for WordPress <= 1.6.0 - Cross-Site Request Forgery
mediumThe Easy Google Analytics for WordPress plugin is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.0. This is due to missing or incorrect nonce validation in the 'ga_admin_set.php' file. This makes it possible for unauthenticated attackers to update the plugin's Google Analytics account an...
- CVSS:
- 6.1
- Affected:
- up to 1.6.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 20, 2023