CVE Database /
CVE-2024-1894
CVE · Medium
CVE-2024-1894 — Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 1.5.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-1894
|
Burst Statistics – Simple WordPress Analytics (Google Analytics Alternative) [burst-statistics] < 1.5.7 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 1.5.7
|
1.5.7 |
2024-03-12 |
—
|
CVE-2024-1894
The Burst Statistics plugin for WordPress contains a stored cross-site scripting vulnerability in versions up to 1.5.6.1 affecting the 'burst_total_pageviews_count' custom meta field. Authenticated users with contributor-level access or higher can inject malicious scripts through inadequate input sanitization and output escaping, which then execute when other users view the affected pages, provided those users have the admin toolbar visible in their profile settings.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings