Stored Cross-Site Scripting Vulnerability in Burst Statistics - Privacy-Friendly Analytics for WordPress
CVE-2024-1894

6.4MEDIUM

Key Information:

Summary

The Burst Statistics plugin for WordPress is impacted by a Stored Cross-Site Scripting vulnerability via the 'burst_total_pageviews_count' custom meta field. This arises from inadequate input sanitization and output escaping on user-supplied data. Authenticated users with contributor-level or higher permissions can exploit this flaw to inject arbitrary web scripts into WordPress pages. These scripts are executed whenever a user with the 'Show Toolbar when viewing site' option enabled in their profile accesses the altered page. This vulnerability underscores the importance of robust security practices in plugin development.

Affected Version(s)

Burst Statistics – Privacy-Friendly Analytics for WordPress * <= 1.5.6.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Craig Smith
.