Arbitrary Web Script Injection Vulnerability in Koko Analytics Plugin
CVE-2024-8662

6.1MEDIUM

Key Information:

Vendor
Dvankooten
Status
Koko Analytics
Vendor
CVE Published:
24 September 2024

Summary

The Koko Analytics plugin for WordPress is susceptible to a serious security flaw that allows for Reflected Cross-Site Scripting attacks. This vulnerability arises from the improper use of the add_query_arg function without appropriate URL escaping. Attackers can exploit this flaw by tricking an unsuspecting user into clicking a malicious link, potentially leading to arbitrary web script execution in the user's context. This issue affects all versions of the plugin up to and including version 1.3.12, rendering a significant number of WordPress installations at risk. Regular updates and security best practices are essential to mitigate the risk associated with this vulnerable plugin.

Affected Version(s)

Koko Analytics * <= 1.3.12

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.