Input validation vulnerability in WP-Matomo Integration (WP-Piwik) 1.0.27

The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to a security issue called Cross-Site Request Forgery. This problem affects versions up to and including 1.0.26 of the plugin. It occurs because the plugin does not have a feature called nonce validation on the show() function. This makes it possible for an unauthenticated attacker to modify the settings of an affected site if they are able to get an administrator to perform an action such as clicking on a link.

Detected in:

Connect Matomo (WP-Matomo, WP-Piwik) fixed vulnerable versions:
WP-Matomo Integration (WP-Piwik) fixed vulnerable versions: >= * < 1.0.27

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.