cleantalk
Vulnerabilities and Security Researches

WP Statistics, CVE-2017-2136

CVE, Research URL

CVE-2017-2136

Application

WP Statistics

Published on
Apr 28, 2017
Research Description
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
Affected versions
max 12.6.7.
Status
vulnerable