CVE · Medium

CVE-2017-2136 — WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-2136 WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 12.0.5 12.0.5 2017-04-13

CVE-2017-2136

WP Statistics before version 12.0.5 contains a stored cross-site scripting flaw that affects several pages within the plugin. The vulnerability arises from improper handling of HTTP Referer headers, allowing attackers to inject malicious code that persists in the application. This issue was separately identified from another vulnerability tracked as JVN#77253951 and was reported to the Japanese authorities for coordinated disclosure with the plugin developer.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.