ZeroHour

CVE-2022-4310

PoC
CVSS 3.1
6.1 medium
EPSS
<1%p49
Published
()
Modified
Description

The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against logged in admin viewing the logs

Vendors
wp-slimstat
Products
slimstat analytics
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.