SQL Injection Vulnerability in Conversios Plugin for Google Analytics 4 and Meta Pixel
CVE-2024-1203

8.8HIGH

Summary

The Conversios plugin for Google Analytics 4 and Meta Pixel, when integrated with Google Tag Manager for WooCommerce, is exposed to SQL Injection vulnerabilities due to improper handling of user-supplied data through the 'valueData' parameter. This flaw allows authenticated attackers with subscriber-level access or higher to inject additional SQL commands into existing queries, resulting in unauthorized access to the database and potential data leaks. Every version up to and including 6.9.1 is affected, emphasizing the need for immediate mitigation measures to safeguard sensitive information within WordPress sites utilizing this plugin.

Affected Version(s)

Conversios – Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce * <= 6.9.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof Zając
.