Stored Cross-Site Scripting Vulnerability in Burst Statistics - Privacy-Friendly Analytics for WordPress
CVE-2024-1894
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 13 March 2024
What is CVE-2024-1894?
The Burst Statistics plugin for WordPress is impacted by a Stored Cross-Site Scripting vulnerability via the 'burst_total_pageviews_count' custom meta field. This arises from inadequate input sanitization and output escaping on user-supplied data. Authenticated users with contributor-level or higher permissions can exploit this flaw to inject arbitrary web scripts into WordPress pages. These scripts are executed whenever a user with the 'Show Toolbar when viewing site' option enabled in their profile accesses the altered page. This vulnerability underscores the importance of robust security practices in plugin development.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Burst Statistics β Privacy-Friendly Analytics for WordPress * <= 1.5.6.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved