Vigil@nce - WordPress Google Analytics MU: Cross Site Request Forgery

This bulletin was written by Vigil@nce : http://vigilance.fr/offer

SYNTHESIS OF THE VULNERABILITY

An attacker can trigger a Cross Site Request Forgery of WordPress
Google Analytics MU, in order to force the victim to perform
operations.

Impacted products: WordPress Plugins

Severity: 2/4

Creation date: 03/03/2014

DESCRIPTION OF THE VULNERABILITY

The Google Analytics MU plugin can be installed on WordPress.

However, the origin of queries is not checked. They can for
example originate from an image included in an HTML document.

An attacker can therefore trigger a Cross Site Request Forgery of
WordPress Google Analytics MU, in order to force the victim to
perform operations.

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/WordPress-Google-Analytics-MU-Cross-Site-Request-Forgery-14351

Articles similaires

Security Vulnerability

24 August 2026

Vigilance.fr - RabbitMQ Server: multiple vulnerabilities dated 24/06/2026

An attacker can use several vulnerabilities of RabbitMQ Server, dated 24/06/2026.

Security Vulnerability

24 August 2026

Vigilance.fr - Perl IO-Compress | IO-Uncompress-Unzip: overload via Per-byte Read Loop, analyzed on 24/06/2026

An attacker can trigger an overload of Perl IO::Compress | IO::Uncompress::Unzip, via Per-byte (…)

Security Vulnerability

24 August 2026

Vigilance.fr - Drupal Modules: multiple vulnerabilities dated 24/06/2026

An attacker can use several vulnerabilities of Drupal Modules, dated 24/06/2026.