4.3
CVE-2015-10001
- EPSS 0.14%
- Veröffentlicht 01.11.2021 09:15:07
- Zuletzt bearbeitet 21.11.2024 02:24:08
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
WP-Stats < 2.52 - Cross-Site Request Forgery
The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads
Mögliche Gegenmaßnahme
WP-Stats: Update to version 2.52, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WP-Stats
Version
[*, 2.52)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wp-stats Project ≫ Wp-stats SwPlatformwordpress Version < 2.52
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.347 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.