GoStats for WordPress Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability exists in the GoStats for WordPress plugin, affecting all versions up to and including 1.4. The issue arises from inadequate nonce validation in the 'gostats_manage()' function, allowing unauthenticated attackers to manipulate the plugin's settings by sending forged requests. Exploitation requires tricking a site administrator into clicking a link that activates the request.

Impact

Exploitation of this vulnerability allows for unauthorized changes to the plugin's settings, specifically the 'gostats_siteid' and 'gostats_server' options.

Remediation

There is no known patch available for this vulnerability. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.

Added: May 27, 2026, 7:21 AM
Updated: May 27, 2026, 7:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.9
remediation
0.0
relevance
9.7
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.