Cross-Site Scripting Vulnerabilities in Count Per Day Plugin for WordPress
CVE-2012-3434
Currently unrated
Summary
The Count Per Day plugin for WordPress is susceptible to multiple cross-site scripting (XSS) vulnerabilities. Attackers can exploit this flaw by injecting arbitrary web scripts or HTML through the parameters: page, datemin, or datemax in the userperspan.php script. This allows for potentially harmful scripts to be executed in the context of the user's browser, leading to session hijacking or defacement of web pages. Users of the affected versions should implement security patches or upgrade to version 3.2 or later.
References
Timeline
Vulnerability Reserved
Vulnerability published