PT-2026-1586 · WordPress · Sharethis Dashboard For Google Analytics

Ifoundbug

·

Publicado

2026-01-07

·

Atualizado

2026-01-07

·

CVE-2025-12540

CVSS v3.1

4.7

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ShareThis Dashboard for Google Analytics plugin for WordPress versions through 3.2.4
Description The plugin is susceptible to Sensitive Information Exposure. The Google Analytics client ID and client secret are stored in plaintext within the publicly accessible plugin source code. An unauthenticated attacker could potentially create a link to the sharethis.com server. If an administrator, logged into the website and Google Analytics, clicks this link, it could share a Google Analytics authorization token with a malicious website.
Recommendations Update to a version beyond 3.2.4.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-12540

Produtos afetados

Sharethis Dashboard For Google Analytics