Web-Stat <= 1.4.0 - API Key Disclosure

2021-02-23 00:00
Ram

Strategic Overview

Status
Patched in 1.4.1
Affected PluginWeb-Stat
Affected Version<= 1.4.0
CVSS7.5High
CVECVE-2021-24167
View all Web-Stat vulnerabilities

Vulnerability Overview

When visiting a site running Web-Stat < 1.4.1, the "wts_web_stat_load_init" function used the visitor’s browser to send an XMLHttpRequest request to https://wts2.one/ajax.htm?action=lookup_WP_account. Issue was partially fixed in 1.4.0, (logged in users still able to see the key) and fully fixed in 1.4.1.

Technical Analysis

REMEDIATION: Update to version 1.4.1, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C