CVE-2015-10001

The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:wp-stats_project:wp-stats:*:*:*:*:*:wordpress:*:*

Information

Published : 2021-11-01 02:15

Updated : 2021-11-03 07:41


NVD link : CVE-2015-10001

Mitre link : CVE-2015-10001


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

wp-stats_project

  • wp-stats