CVE Database /
CVE-2018-1000556
CVE · Medium
CVE-2018-1000556 — WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] >= 12.0.2 - <= 12.0.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2018-1000556
|
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] >= 12.0.2 - <= 12.0.5 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
12.0.2–12.0.5
|
12.0.5 |
2018-06-26 |
—
|
CVE-2018-1000556
The WP Statistics plugin versions 12.0.2 through 12.0.5 contain a reflected cross-site scripting vulnerability in the deletion function that affects WordPress 4.8 and later. An attacker could craft a malicious URL containing script code and trick a user into clicking the link, allowing the execution of arbitrary JavaScript in the victim's browser. This could enable attackers to steal session cookies, inject malicious code, or perform other client-side attacks. The vulnerability requires user interaction, as the victim must visit the attacker-supplied URL for the payload to execute.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings