PT-2024-17377 · WordPress · Reactflow Visitor Recording/Heatmaps
Dale Mavers
+1
·
Published
2024-12-21
·
Updated
2024-12-21
·
CVE-2024-11975
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Reactflow Visitor Recording and Heatmaps plugin for WordPress versions up to, and including, 1.0.10
Description
The issue is due to missing or incorrect nonce validation affecting the
wpnonce parameter. This allows unauthenticated attackers to inject malicious web scripts via a forged request if they can trick a site administrator into performing an action, such as clicking on a link.Recommendations
For versions up to, and including, 1.0.10, update to a version that includes the fix for the nonce validation issue. As a temporary workaround, consider restricting access to the plugin's functionality to minimize the risk of exploitation. Avoid using the
wpnonce parameter in a way that could be manipulated by an attacker until the issue is resolved.Fix
XSS
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Reactflow Visitor Recording/Heatmaps