Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product.
References
Link | Resource |
---|---|
https://wordpress.org/plugins/wp-statistics/ | Product Third Party Advisory |
https://wordpress.org/plugins/wp-statistics/#developers | Release Notes Third Party Advisory |
https://jvn.jp/en/jp/JVN15241647/index.html | Release Notes Third Party Advisory |
Configurations
Information
Published : 2022-06-12 22:15
Updated : 2022-06-17 11:51
NVD link : CVE-2022-27231
Mitre link : CVE-2022-27231
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
veronalabs
- wp_statistics