First published: Fri Jul 07 2017(Updated: )
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WP Statistics | <=12.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-10991 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2017-10991, update the WP Statistics plugin to a version higher than 12.0.9.
CVE-2017-10991 can allow attackers to execute arbitrary JavaScript in the context of the affected WordPress site, leading to session hijacking or defacement.
CVE-2017-10991 affects WP Statistics plugin versions up to and including 12.0.9.
Yes, exploiting CVE-2017-10991 requires an authenticated user to access the vulnerable functionality.