Логотип exploitDog
bind:CVE-2015-10001
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2015-10001

Количество 2

Количество 2

nvd логотип

CVE-2015-10001

больше 4 лет назад

The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2wcw-gx74-hx8q

больше 3 лет назад

The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2015-10001

The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
github логотип
GHSA-2wcw-gx74-hx8q

The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу