CVE-2017-10991: XSS
Published Jul 7, 2017
·Updated
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wpsreferrerspage page.
Affected Software
1 affected component
Wp-statistics Wp Statistics Wordpress<=12.0.9
Event History
Jul 7, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-10991?
CVE-2017-10991 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2017-10991?
To fix CVE-2017-10991, update the WP Statistics plugin to a version higher than 12.0.9.
3
What are the potential impacts of CVE-2017-10991?
CVE-2017-10991 can allow attackers to execute arbitrary JavaScript in the context of the affected WordPress site, leading to session hijacking or defacement.
4
Which versions of the WP Statistics plugin are affected by CVE-2017-10991?
CVE-2017-10991 affects WP Statistics plugin versions up to and including 12.0.9.
5
Is authentication required to exploit CVE-2017-10991?
Yes, exploiting CVE-2017-10991 requires an authenticated user to access the vulnerable functionality.