CVE · Medium

CVE-2024-1894 — Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 1.5.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1894 Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 1.5.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.5.7 1.5.7 2024-03-12

CVE-2024-1894

The Burst Statistics plugin for WordPress contains a stored cross-site scripting vulnerability in versions up to 1.5.6.1 affecting the 'burst_total_pageviews_count' custom meta field. Authenticated users with contributor-level access or higher can inject malicious scripts through inadequate input sanitization and output escaping, which then execute when other users view the affected pages, provided those users have the admin toolbar visible in their profile settings.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.