Tracking Code Manager < 1.11.5 - Denial of Service
2017-05-10 00:00
DefenceCodeStrategic Overview
StatusPatched in 1.11.5
Affected PluginTracking Code Manager
Affected Version
<= 1.11.4CVSS7.5High
CVE
N/AVulnerability Overview
The Tracking Code Manager for WordPress is vulnerable to Denial of Service attacks in versions up to, and including, 1.11.4. This is due to the ability of users to make a recursive call to the 'tcmp_do_action' function. Due to an additional Cross-Site Request Forgery vulnerability, this makes it possible for unauthenticated attackers to render a site unresponsive until a restart.
Technical Analysis
REMEDIATION: Update to version 1.11.5, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C