Stored Cross-Site Scripting Vulnerability in Burst Statistics - Privacy-Friendly Analytics for WordPress
CVE-2024-1894
6.4MEDIUM
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 13 March 2024
Summary
The Burst Statistics plugin for WordPress is impacted by a Stored Cross-Site Scripting vulnerability via the 'burst_total_pageviews_count' custom meta field. This arises from inadequate input sanitization and output escaping on user-supplied data. Authenticated users with contributor-level or higher permissions can exploit this flaw to inject arbitrary web scripts into WordPress pages. These scripts are executed whenever a user with the 'Show Toolbar when viewing site' option enabled in their profile accesses the altered page. This vulnerability underscores the importance of robust security practices in plugin development.
Affected Version(s)
Burst Statistics – Privacy-Friendly Analytics for WordPress * <= 1.5.6.1
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Craig Smith