XSS Vulnerability in Count per Day Plugin for WordPress
CVE-2013-7472
6.1MEDIUM
Summary
The Count per Day plugin version prior to 3.2.6 for WordPress contains a vulnerability that allows attackers to exploit the wp-admin/?page=cpd_metaboxes URL by manipulating the daytoshow parameter. This flaw enables them to execute arbitrary JavaScript in the context of the user's session, potentially leading to data exposure and unauthorized actions.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved