Логотип exploitDog
bind:CVE-2024-2194
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-2194

Количество 3

Количество 3

nvd логотип

CVE-2024-2194

почти 2 года назад

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Средний
github логотип

GHSA-wjm8-g6q3-jwm2

почти 2 года назад

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
EPSS: Средний
fstec логотип

BDU:2024-04813

почти 2 года назад

Уязвимость плагина WP Statistics системы управления содержимым сайта WordPress, позволяющая нарушителю выполнить межсайтовый скриптинг XSS

CVSS3: 7.2
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-2194

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
35%
Средний
почти 2 года назад
github логотип
GHSA-wjm8-g6q3-jwm2

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS3: 7.2
35%
Средний
почти 2 года назад
fstec логотип
BDU:2024-04813

Уязвимость плагина WP Statistics системы управления содержимым сайта WordPress, позволяющая нарушителю выполнить межсайтовый скриптинг XSS

CVSS3: 7.2
35%
Средний
почти 2 года назад

Уязвимостей на страницу