Tracking Code Manager < 1.11.5 - Denial of Service

2017-05-10 00:00
DefenceCode

Strategic Overview

Status
Patched in 1.11.5
Affected PluginTracking Code Manager
Affected Version<= 1.11.4
CVSS7.5High
CVEN/A
View all Tracking Code Manager vulnerabilities

Vulnerability Overview

The Tracking Code Manager for WordPress is vulnerable to Denial of Service attacks in versions up to, and including, 1.11.4. This is due to the ability of users to make a recursive call to the 'tcmp_do_action' function. Due to an additional Cross-Site Request Forgery vulnerability, this makes it possible for unauthenticated attackers to render a site unresponsive until a restart.

Technical Analysis

REMEDIATION: Update to version 1.11.5, or a newer patched version --- IDENTIFIER: CWE-400 (Uncontrolled Resource Consumption) The product does not properly control the allocation and maintenance of a limited resource.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C