The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions up to, and including, 2.15.0. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability arises from the get_cell_content() function applying urld [truncated]
The Independent Analytics plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) in all versions up to and including 2.14.9. The vulnerability stems from a publicly accessible REST API endpoint at /wp-json/iawp/search that accepts attacker-controlled referrer_url values when a signature validation check passes. The signature mechanism is insufficiently protected because the signature is [truncated]