Unauthenticated Cross-Site Scripting Vulnerability in Seriously Simple Stats Plugin
CVE-2024-8738

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
24 September 2024

Summary

The Seriously Simple Stats plugin for WordPress contains a vulnerability that exposes it to reflected cross-site scripting due to the improper use of add_query_arg without adequate escaping on URLs. This flaw affects all versions up to and including 1.6.0. As a result, unauthenticated attackers may inject malicious web scripts into linked pages, which can execute if a user is misled into clicking a compromised link. This vulnerability highlights the importance of adhering to best practices for input handling and sanitization within web applications.

Affected Version(s)

Seriously Simple Stats * <= 1.6.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dale Mavers
.