vendor:
3dady real-time web stats
by:
UnD3sc0n0c1d0
8.8
CVSS
HIGH
Stored Cross Site Scripting (XSS)
79
CWE
Product Name: 3dady real-time web stats
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:wordpress:wordpress
Platforms Tested: Debian / WordPress 6.0.1
2022
WordPress Plugin 3dady real-time web stats 1.0 – Stored Cross Site Scripting (XSS)
The 3dady real-time web stats WordPress plugin is vulnerable to stored XSS. Specifically in the dady_input_text and dady2_input_text fields because the user's input is not properly sanitized which allows the insertion of JavaScript code that can exploit the vulnerability.
Mitigation:
Input validation and sanitization should be implemented to prevent malicious code from being executed.