Search This Blog
Popular Posts
-
Hello there! My blog post 'Spikes' was published on Sept. 22nd; however, the post before it called 'Flow' was published on...
-
WordPress has evolved to be much more than just a blogging platform, from online stores to full-on business platforms, there is ve...
-
I will publish an article only when I have something important to say. That's what I reminded myself every time the egocentric ...
-
This entry was posted in Research, WordPress Security on March 1, 2017 by Mark Maunder 43 Replies Today we are posting an in-dep...
-
Written By ESR News Blog Editor Thomas Ahearn Information security is a top priority for background screening firms in today's dig...
-
The New York City Housing Authority (NYCHA) says rumors claiming that three Harlem housing projects have been sold to a "billionaire ...
-
I've been blogging with Wordpress since March. That's a little over three months of writing new posts at least twice a week. (Go m...
-
The United States government earlier this year officially accused Russia of interfering with the US elections. Earlier this year on Octo...
-
Are you planning to accept payments on your WordPress site? Then you've probably already considered the usual eCommerce payment gatewa...
-
We've covered various topic around the subject of WordPress SEO giving you tips and pointers and how we can make your website ...
Blog Archive
- December (18)
- November (29)
- October (27)
- September (29)
- August (31)
- July (30)
- June (29)
- May (29)
- April (30)
- March (31)
- February (28)
- January (31)
- December (31)
- November (30)
- October (31)
- September (30)
- August (43)
- July (42)
- June (33)
- May (43)
- April (36)
- March (37)
- February (31)
- January (4)
- December (1)
- November (1)
- October (24)
- September (24)
- August (25)
- July (28)
- June (18)
- September (1)
Total Pageviews
Blogroll
Vulnerability patched in Google Analyticator Wordpress Plugin
Symantec A vulnerability which exposed Wordpress websites running the Google Analyticator plugin has been patched.
Revealed by security researcher Nitin Venkatesh on Friday, a security advisory posted on Full Disclosure detailed a flaw found within the Google Analyticator Wordpress plugin, used by webmasters to view Google Analytics data within a Wordpress dashboard.
The plugin, downloaded over 3.5 million times, contains a number of widgets for displaying analytics data in the admin dashboard and on blogs, but a security issue has been found within cache settings.
Discovered in version 6.4.9.3, the security vulnerability allows for Cross-Site Request Forgery (CSRF) and for "the administrative actions allowed by the plugin to be exploited [...] which could be used to disrupt the functionality provided by the plugin," according to Venkatesh. The researcher says that in theory, an authenticated user could visit a website belonging to an attacker where requests -- such as cache clearing and resets -- could be submitted through vulnerable URLS using the authenticated user's session.
Actions could then be performed without the user's consent or knowledge.
The vulnerability was submitted on the Wordpress support forum on June 2 with proof-of-concept examples. Following discussion of the flaw, the Google Analyticator plugin developer updated and patched the security vulnerability on June 18. In order to avoid encountering this security vulnerability, web developers should update their plugin to version 6.4.9.3.
In May a critical security flaw was discovered in the Twenty Fifteen theme and plugin, placing millions of users at risk. Installed in new Wordpress websites by default, the theme's genericons package is loaded with an insecure file dubbed example.html, which is vulnerable to a Document Object Model (DOM)-based XSS vulnerability.
Read on: Top picks
Source: Vulnerability patched in Google Analyticator Wordpress Plugin
0 comments:
Post a Comment