The Analytics Insights for Google Analytics 4 (AIWP) WordPress plugin before 6.3 is vulnerable to Open Redirect due to insufficient validation on the redirect oauth2callback.php file. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
History

Wed, 09 Oct 2024 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Deconf
Deconf analytics Insights
Weaknesses CWE-601
CPEs cpe:2.3:a:deconf:analytics_insights:*:*:*:*:*:wordpress:*:*
Vendors & Products Deconf
Deconf analytics Insights
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-02-12T16:05:58.073Z

Updated: 2024-08-01T17:41:16.271Z

Reserved: 2024-01-05T14:49:48.529Z

Link: CVE-2024-0250

cve-icon Vulnrichment

Updated: 2024-08-01T17:41:16.271Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-12T16:15:08.500

Modified: 2024-10-09T13:19:36.667

Link: CVE-2024-0250

cve-icon Redhat

No data.