vendor:
WordPress Free Counter Plugin
by:
Panagiotis Vagenas
N/A
CVSS
N/A
Stored XSS
CWE
Product Name: WordPress Free Counter Plugin
Affected Version From: 1.1
Affected Version To: 1.1
Patch Exists: NO
Related CWE: CVE-2015-4084
CPE:
Platforms Tested: WordPress 4.2.2
2015
WordPress Free Counter Plugin [Stored XSS]
Any authenticated or non-authenticated user can perform a stored XSS attack simply by exploiting wp_ajax_nopriv_check_stat action. Plugin uses a widget to display website's visits, so any page that contains this widget will also load the malicious JS code.
Mitigation:
No official solution yet exists.