What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in Conversios All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce plugin <= 5.2.3 leads to plugin settings change.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in Conversios All-in-one Google Analytics, Pixels and Product Feed Manager for WooCommerce plugin <= 5.2.3 leads to plugin settings change.
Explanation of Vulnerability in Simple Terms
The Conversios Google Analytics plugin for WooCommerce versions up to 5.2.3 are vulnerable to cross-site request forgery (CSRF). An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted actions on the site without their knowledge. This could modify plugin settings or trigger unintended operations.
What an attacker can do
Trick a site admin into visiting a malicious page that modifies plugin settings or performs actions without their consent.
Potential impact on your site
Plugin settings could be altered or actions executed without your knowledge if you visit a malicious link while logged in.
Conditions required to exploit
Admin must be logged in and visit an attacker-controlled webpage; no special privileges or direct site access required.
Key dates
External resources
Related vulnerabilities