Impact
Unauthenticated Cross Site Request Forgery in the Tracking Code Manager plugin allows an attacker to submit malicious scripts that are stored and later executed in the context of victim browsers. This stored XSS can lead to session hijacking, defacement, or credential theft for users who view the injected content. The weakness is a classic CSRF flaw (CWE-352) that enables the attacker to bypass authentication checks. The impact is primarily a loss of confidentiality and integrity for site users, with potential availability issues if the site is heavily compromised.
Affected Systems
Data443 Risk Mitigation, Inc. offers the Tracking Code Manager plugin for WordPress. Versions 2.6.0 and earlier are affected. The vendor recommends upgrading to at least version 2.7.0 to address the flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. While the EPSS score is not available, the flaw is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation yet. The likely attack vector involves a crafted CSRF request sent by an authenticated user with sufficient privileges to modify tracking scripts. Because the attacker does not need prior privileges, the risk is elevated, especially on sites where the plugin’s administrative interface is exposed to attackers who can obtain session cookies.
OpenCVE Enrichment