Google Analytics MU < 2.4 - Cross-Site Request Forgery
highThe Google Analytics MU plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.4. This is due to missing or incorrect nonce validation on the UAID function. This makes it possible for unauthenticated attackers to arbitrarily manipulate settings via a forged request granted they can trick...
- CVSS:
- 8.8
- Affected:
- up to 2.3.1
- Fixed in:
- 2.4
- Disclosed:
- Mar 3, 2014