PT-2022-17201 · WordPress · Wp Statistics

Muhammad Zeeshan

·

Published

2022-02-24

·

Updated

2022-03-03

·

CVE-2022-25306

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Statistics versions up to and including 13.1.5
Description The issue arises from insufficient escaping and sanitization of the browser parameter in the ~/includes/class-wp-statistics-visitor.php file, allowing attackers to inject arbitrary web scripts onto several pages. These scripts execute when site administrators view a site's statistics.
Recommendations For versions up to and including 13.1.5, update to a version that includes the necessary escaping and sanitization fixes for the browser parameter to prevent Cross-Site Scripting attacks. As a temporary workaround, consider restricting access to the statistics pages for site administrators until a patch is available.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25306

Affected Products

Wp Statistics