Executive brief
The WooCommerce Conversion Tracking plugin for WordPress, which helps store owners track marketing data, contains a security flaw that could allow an attacker to trick an administrator into performing unintended actions. By convincing a logged-in user to click a malicious link or visit a specific webpage, an attacker could potentially modify plugin settings or access sensitive tracking information. This could lead to unauthorized configuration changes or the exposure of marketing data.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the weDevs WooCommerce Conversion Tracking plugin through version 2.0.10. The issue stems from a lack of proper nonce validation or similar anti-CSRF protections on sensitive administrative functions. An unauthenticated attacker can exploit this by crafting a malicious request and tricking a privileged user (such as an administrator) into executing it via social engineering (e.g., a malicious link). Successful exploitation could allow the attacker to perform actions with the privileges of the victim, potentially leading to broken access control or unauthorized data disclosure. The vulnerability is addressed in version 2.0.11.
Affected products
- weDevs WooCommerce Conversion Tracking <= 2.0.10
Timeline
- 2022-12-06: disclosed: Reported by István Márton
- 2023-09-04: advisory: Patchstack published advisory
- 2023-09-04: patched: Fixed in version 2.0.11
- 2026-06-11: other: NVD publication date