WordPress Popular Posts <= 6.0.5 - Unauthenticated Views Changes
2022-11-18 00:00
Tsubasa IinumaStrategic Overview
StatusPatched in 6.1.0
Affected PluginWP Popular Posts
Affected Version
<= 6.0.5CVSS5.3Medium
CVE
CVE-2022-43468Vulnerability Overview
The WordPress Popular Posts plugin for WordPress is vulnerable to Unauthenticated Views Changes in versions up to, and including, 6.0.5. This is due to a lack of user input validation on a REST endpoint that results in unprotected behavior in the 'update_views_count' function. This makes it possible for unauthenticated attackers to manipulate and potentially change the views count endpoint.
Technical Analysis
REMEDIATION: Update to version 6.1.0, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C