vendor:
NewStatPress
by:
Adrián M. F.
7.5
CVSS
HIGH
Authenticated SQLi, Authenticated XSS
89, 79
CWE
Product Name: NewStatPress
Affected Version From: 2000.9.8
Affected Version To: 2000.9.9
Patch Exists: YES
Related CWE: CVE-2015-4062, CVE-2015-4063
CPE: a:wordpress:newstatpress
Tags: cve,cve2015,xss,wordpress,wp-plugin,wp,newstatpress,packetstorm
CVSS Metrics: CVSS:2.0/AV:N/AC:M/Au:S/C:N/I:P/A:N
Nuclei References:
https://packetstormsecurity.com/files/132038/, https://wordpress.org/plugins/newstatpress/, http://packetstormsecurity.com/files/132038/WordPress-NewStatPress-0.9.8-Cross-Site-Scripting-SQL-Injection.html, https://nvd.nist.gov/vuln/detail/CVE-2015-4063, https://wordpress.org/plugins/newstatpress/changelog/
Nuclei Metadata: {'max-request': 2, 'verified': True, 'framework': 'wordpress', 'vendor': 'newstatpress_project', 'product': 'newstatpress'}
Platforms Tested:
2015
Multiple vulnerabilities in WordPress plugin “NewStatPress”
The plugin "NewStatPress" in WordPress is vulnerable to an authenticated SQL injection vulnerability (CVE-2015-4062) and an authenticated XSS vulnerability (CVE-2015-4063). The SQL injection vulnerability can be exploited by an authenticated user by manipulating the "where1" parameter in the "admin.php" page. The XSS vulnerability can also be exploited by an authenticated user by manipulating the "where1" parameter in the same page.
Mitigation:
Update to version 0.9.9 of the plugin.