Input validation vulnerability in Slimstat Analytics 4.8.4

The Slimstat Analytics plugin for WordPress is vulnerable to an attack known as Cross-Site Request Forgery. This type of attack can happen when a website administrator clicks on a link or performs another action that has been crafted by an attacker. The vulnerability exists in versions of the plugin up to and including 4.8.3 and is due to incorrect nonce validation on the update_settings function. This means that the attacker can inject malicious web scripts into the victim’s browser without them knowing.

Detected in:

Slimstat Analytics fixed vulnerable versions: >= * < 4.8.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.