WordPress Popular Posts <= 6.0.5 - Unauthenticated Views Changes

2022-11-18 00:00
Tsubasa Iinuma

Strategic Overview

Status
Patched in 6.1.0
Affected PluginWP Popular Posts
Affected Version<= 6.0.5
CVSS5.3Medium
CVECVE-2022-43468
View all WP Popular Posts vulnerabilities

Vulnerability Overview

The WordPress Popular Posts plugin for WordPress is vulnerable to Unauthenticated Views Changes in versions up to, and including, 6.0.5. This is due to a lack of user input validation on a REST endpoint that results in unprotected behavior in the 'update_views_count' function. This makes it possible for unauthenticated attackers to manipulate and potentially change the views count endpoint.

Technical Analysis

REMEDIATION: Update to version 6.1.0, or a newer patched version --- IDENTIFIER: CWE-284 (Improper Access Control) The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C