vendor:
NewStatPress
by:
Summer of Pwnage
7,5
CVSS
HIGH
Persistent Cross-Site Scripting (XSS)
79
CWE
Product Name: NewStatPress
Affected Version From: 1.2.4
Affected Version To: 1.2.4
Patch Exists: YES
Related CWE: N/A
CPE: a:lechab:newstatpress
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: WordPress
2016
Persistent Cross-Site Scripting in the WordPress NewStatPress Plugin
A persistent Cross-Site Scripting (XSS) vulnerability has been found in the WordPress NewStatPress plugin. By using this vulnerability an attacker can inject malicious JavaScript code into the application, which will execute within the browser of any user who views the relevant application content.
Mitigation:
This issue has been addressed in NewStatPress version 1.2.5. This version can be download from the NewStatPress GitHub account.