Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Michael Kapfer

Researcher fromHSASec
#30422of 53,638
8.6Total CVSS
Vulnerabilities · 2
Medium
2
PT-2021-8380
4.3
2021-11-01
WordPress · Wp-Stats · CVE-2015-10001
**Name of the Vulnerable Software and Affected Versions** WP-Stats WordPress plugin versions prior to 2.52 **Description** The issue allows an attacker to make logged-in high-privilege users change settings and set Cross-Site Scripting payloads due to the lack of a CSRF check when saving settings and the failure to escape some settings when outputting them. **Recommendations** For WP-Stats WordPress plugin versions prior to 2.52, update to version 2.52 or later to resolve the issue. As a temporary workaround, consider restricting access to the settings page to minimize the risk of exploitation.
PT-2019-7273
4.3
2019-08-14
WordPress · Newstatpress · CVE-2015-9314
**Name of the Vulnerable Software and Affected Versions** newstatpress plugin versions prior to 1.0.4 for WordPress **Description** The issue is related to a Cross-Site Scripting (XSS) vulnerability. It is associated with the Referer header. **Recommendations** For versions prior to 1.0.4, update to version 1.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the Referer header until the update is applied.