QID 150838
Date Published: 2024-03-20
QID 150838: WordPress WP Statistics Plugin: Stored Cross-Site Scripting (XSS) Vulnerability (CVE-2024-2194)
WP Statistics is a WordPress plugin for understanding the traffic and user data of website. It provides detailed information about the browser, search engine, and most popular content (categorized by tags, categories, and authors) of website's visitors.
Affected version of WP Statistics plugin is vulnerable to Stored Cross-Site Scripting (XSS) via the URL search parameter due to insufficient input sanitization and output escaping.
Affected Versions:
WP Statistics prior to version 14.5.1
QID Detection Logic:(Unauthenticated)
This QID checks for vulnerable version of WP Statistics plugin running on the target WordPress application.
Successful exploitation of this vulnerability could allow an unauthenticated attacker to inject arbitrary JavaScript code in pages that will execute whenever a user accesses an injected page.
- WP Statistics Changelog -
raw.githubusercontent.com/wp-statistics/wp-statistics/master/CHANGELOG.md
CVEs related to QID 150838
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| WP Statistics Downloads |
|