CVE-2025-1507

The ShareThis Dashboard for Google Analytics plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_actions() function in all versions up to, and including, 3.2.1. This makes it possible for unauthenticated attackers to disable all features.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sharethis:dashboard_for_google_analytics:*:*:*:*:*:wordpress:*:*

History

27 Mar 2025, 01:35

Type Values Removed Values Added
Summary
  • (es) El complemento ShareThis Dashboard para Google Analytics para WordPress es vulnerable a la modificación no autorizada de datos debido a la falta de una comprobación de capacidad en la función handle_actions() en todas las versiones hasta la 3.2.1 incluida. Esto permite que atacantes no autenticados deshabiliten todas las funciones.
CPE cpe:2.3:a:sharethis:dashboard_for_google_analytics:*:*:*:*:*:wordpress:*:*
References () https://plugins.trac.wordpress.org/changeset/3255511/googleanalytics/trunk/class/core/class-ga-controller-core.php - () https://plugins.trac.wordpress.org/changeset/3255511/googleanalytics/trunk/class/core/class-ga-controller-core.php - Patch
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/314b8638-15e7-461d-a705-3858fe6813e7?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/314b8638-15e7-461d-a705-3858fe6813e7?source=cve - Third Party Advisory
First Time Sharethis
Sharethis dashboard For Google Analytics

14 Mar 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-14 09:15

Updated : 2025-03-27 01:35


NVD link : CVE-2025-1507

Mitre link : CVE-2025-1507

CVE.ORG link : CVE-2025-1507


JSON object : View

Products Affected

sharethis

  • dashboard_for_google_analytics
CWE
CWE-862

Missing Authorization