Executive brief
The GoStats for WordPress plugin, which integrates website traffic statistics into WordPress sites, contains a security flaw that allows unauthorized setting changes. By tricking a site administrator into clicking a malicious link, an attacker can remotely modify the plugin's configuration, such as the site ID or server settings. This could lead to the redirection of traffic data or disruption of website analytics.
Technical details
The GoStats for WordPress plugin is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the gostats_manage() function. An unauthenticated attacker can exploit this by inducing a logged-in administrator to submit a forged web request, typically via social engineering or a malicious link. Successful exploitation allows the attacker to modify the 'gostats_siteid' and 'gostats_server' options in the WordPress database. This vulnerability affects all versions of the plugin up to and including 1.4.
Affected products
- GoStats GoStats for WordPress Up to, and including, 1.4
Timeline
- 2026-05-27: disclosed: Vulnerability published by Wordfence and NVD.