Cross-Site Scripting Vulnerability in WP Slimstat Plugin for WordPress
CVE-2015-1204
Currently unrated
Summary
A cross-site scripting (XSS) vulnerability exists in the Save Filters functionality of the WP Slimstat plugin prior to version 3.9.2. This flaw allows remote attackers to inject arbitrary web scripts or HTML by manipulating the 'fs[resource]' parameter in the 'wp-slim-view-2' page within the WordPress admin dashboard. If exploited, this vulnerability can lead to unauthorized access and compromise the security of the affected website.
References
Timeline
Vulnerability Reserved
Vulnerability published