ZeroHour

CVE-2024-0250

PoC
CVSS 3.1
6.1 medium
EPSS
1%p68
Published
()
Modified
Description

The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

Vendors
deconf
Products
analytics insights
Ecosystems
WordPress
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.