Cross-Site Scripting Vulnerability in WP Slimstat Plugin for WordPress
CVE-2015-1204

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
21 January 2015

Summary

A cross-site scripting (XSS) vulnerability exists in the Save Filters functionality of the WP Slimstat plugin prior to version 3.9.2. This flaw allows remote attackers to inject arbitrary web scripts or HTML by manipulating the 'fs[resource]' parameter in the 'wp-slim-view-2' page within the WordPress admin dashboard. If exploited, this vulnerability can lead to unauthorized access and compromise the security of the affected website.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.