Unauthenticated Cross-Site Scripting Vulnerability in Seriously Simple Stats Plugin
CVE-2024-8738
What is CVE-2024-8738?
The Seriously Simple Stats plugin for WordPress contains a vulnerability that exposes it to reflected cross-site scripting due to the improper use of add_query_arg without adequate escaping on URLs. This flaw affects all versions up to and including 1.6.0. As a result, unauthenticated attackers may inject malicious web scripts into linked pages, which can execute if a user is misled into clicking a compromised link. This vulnerability highlights the importance of adhering to best practices for input handling and sanitization within web applications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Seriously Simple Stats * <= 1.6.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved