CVE-2024-8513: QA Analytics <= 4.1.1.1 - Missing Authorization to Unauthenticated Settings Update
The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajaxsavepluginconfig() function in all versions up to, and including, 4.1.1.1. This makes it possible for unauthenticated attackers to update the plugin's settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8513?
CVE-2024-8513 has been classified as a high severity vulnerability due to the potential for unauthorized data modification.
How do I fix CVE-2024-8513?
To fix CVE-2024-8513, update the QA Analytics – Web Analytics Tool plugin to version 4.1.0.1 or later, which includes the necessary capability checks.
What versions of the QA Analytics plugin are affected by CVE-2024-8513?
CVE-2024-8513 affects all versions of the QA Analytics plugin for WordPress up to and including 4.1.0.0.
Exploit details for CVE-2024-8513?
CVE-2024-8513 allows attackers to modify configuration settings without authorization due to a missing capability check.
Is there a workaround for CVE-2024-8513?
A potential workaround for CVE-2024-8513 is to manually restrict access to the plugin's configuration settings until an update can be applied.