PT-2025-11252 · WordPress · Sharethis Dashboard For Google Analytics
Published
2025-03-14
·
Updated
2025-03-27
·
CVE-2025-1507
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
ShareThis Dashboard for Google Analytics plugin for WordPress versions up to, and including, 3.2.1
Description:
The issue allows unauthorized modification of data due to a missing capability check on the
handle actions() function. This makes it possible for unauthenticated attackers to disable all features.Recommendations:
For versions up to, and including, 3.2.1, update to a version that includes a fix for the missing capability check in the
handle actions() function.
As a temporary workaround, consider disabling the handle actions() function until a patch is available.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sharethis Dashboard For Google Analytics