WordPress Matomo Analytics Plugin <= 5.1.0 is vulnerable to CSRF
-
Through SolidWP and through patchstack.com I get the warning that there is a vulnerability to Cross Site Request Forgery (CSRF) in the current version of the Matomo Analytics Plugin 5.1 – but there seems to be no fix yet. Now I’m wondering if i should disable/delete the Matomo Analytics Plugin on all WordPress installations – or be patient and wait for an update? The vulnerability is rated “moderate” –?so I guess on a ‘normal’ installation the risk should be low to get hacked through this vulnerability. But it would be nice if somebody could elaborate if we should worry – and when we can expect a fix. Thank you!
- You must be logged in to reply to this topic.