CVE · Medium

CVE-2018-1000556 — WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] >= 12.0.2 - <= 12.0.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2018-1000556 WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] >= 12.0.2 - <= 12.0.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 12.0.2–12.0.5 12.0.5 2018-06-26

CVE-2018-1000556

The WP Statistics plugin versions 12.0.2 through 12.0.5 contain a reflected cross-site scripting vulnerability in the deletion function that affects WordPress 4.8 and later. An attacker could craft a malicious URL containing script code and trick a user into clicking the link, allowing the execution of arbitrary JavaScript in the victim's browser. This could enable attackers to steal session cookies, inject malicious code, or perform other client-side attacks. The vulnerability requires user interaction, as the victim must visit the attacker-supplied URL for the payload to execute.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.