Input validation vulnerability in Hotspots Analytics 4.0.12

The Hotspots Analytics plugin for WordPress has a security issue called Cross-Site Request Forgery. This affects all versions up to 4.0.12. The problem is that the plugin does not properly check for a unique code when performing a certain task. This allows attackers to make changes to the plugin’s settings and insert harmful code into websites, as long as they can trick the website administrator into taking an action, like clicking a link.

Detected in:

Hotspots Analytics open vulnerable versions: >= * <= 4.0.12

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.