cleantalk
Vulnerabilities and Security Researches

WP Statistics, CVE-2022-1005

CVE, Research URL

CVE-2022-1005

Application

WP Statistics

Published on
Jun 08, 2022
Research Description
The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode characters
Affected versions
Min -, max 12.0.9.
Status
vulnerable