What the vulnerability does
01Description
Missing Authorization vulnerability in Cornel Raiu WP Search Analytics search-analytics.This issue affects WP Search Analytics: from n/a through <= 1.4.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Cornel Raiu WP Search Analytics search-analytics.This issue affects WP Search Analytics: from n/a through <= 1.4.9.
Explanation of Vulnerability in Simple Terms
WP Search Analytics versions 1.4.9 and earlier lack proper authorization checks, allowing authenticated users with low privileges to modify data they should not have access to. An attacker with a basic user account can alter search analytics records or settings. The vulnerability requires an existing user account but no special interaction. Update to a version newer than 1.4.9.
What an attacker can do
Modify search analytics data or settings without proper authorization.
Potential impact on your site
Unauthorized users can tamper with search analytics records, compromising data integrity and reporting accuracy.
Conditions required to exploit
Attacker must have a low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities