Stored Cross-Site Scripting Vulnerability in Burst Statistics - Privacy-Friendly Analytics for WordPress
CVE-2024-1894
5.4MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 13 March 2024
What is CVE-2024-1894?
The Burst Statistics plugin for WordPress is impacted by a Stored Cross-Site Scripting vulnerability via the 'burst_total_pageviews_count' custom meta field. This arises from inadequate input sanitization and output escaping on user-supplied data. Authenticated users with contributor-level or higher permissions can exploit this flaw to inject arbitrary web scripts into WordPress pages. These scripts are executed whenever a user with the 'Show Toolbar when viewing site' option enabled in their profile accesses the altered page. This vulnerability underscores the importance of robust security practices in plugin development.
Affected Version(s)
Burst Statistics – Privacy-Friendly Analytics for WordPress * <= 1.5.6.1