CVE · Medium

CVE-2017-2147 — WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] <= 12.0.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2017-2147 WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] <= 12.0.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 12.0.4 12.0.4 2017-04-13

CVE-2017-2147

The WP Statistics plugin for WordPress through version 12.0.4 is affected by a stored cross-site scripting flaw that allows attackers to inject malicious scripts into the application, which are then executed when other users access the affected content. This vulnerability, tracked as CVE-2017-2147, was discovered by Gen Sato at Mitsui Bussan Secure Directions, Inc., and coordinated through JPCERT/CC's partnership program with the developer.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.