CVE Database /
CVE-2019-12566
CVE · Medium
CVE-2019-12566 — WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.6.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2019-12566
|
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.6.1 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 12.6.6.1
|
12.6.6.1 |
2019-05-31 |
—
|
CVE-2019-12566
The WP Statistics plugin before version 12.6.6.1 contains a stored cross-site scripting vulnerability in its pages functionality. An attacker with Editor role permissions could inject malicious JavaScript into a post title, which would then execute when an administrator views the affected content. This allows a lower-privileged user to compromise administrator accounts through a crafted post title.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings