Input validation vulnerability in Journey Analytics 1.0.12

The Journey Analytics plugin for WordPress is vulnerable to a type of cyber attack called Cross-Site Request Forgery. This means that, in versions up to and including 1.0.12, someone unauthenticated (not logged in) would be able to get access to the analytics data without permission if they were able to get a site administrator to take an action like clicking on a link. This is because the plugin doesn’t have the correct security measures in place to stop this from happening.

Detected in:

Journey Analytics open vulnerable versions: >= * <= 1.0.12

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.