CVE-2019-10864: XSS
Published Apr 23, 2019
·Updated
The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.
Affected Software
1 affected component
VeronaLabs Wp Statistics Wordpress<=12.6.2
Remediation
Event History
Apr 23, 2019
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-10864?
The severity of CVE-2019-10864 is categorized as medium due to its potential impact on web applications.
2
How do I fix CVE-2019-10864?
To fix CVE-2019-10864, update the WP Statistics plugin to version 12.6.3 or later.
3
Who is affected by CVE-2019-10864?
CVE-2019-10864 affects users of the WP Statistics plugin version 12.6.2 and earlier on WordPress.
4
What type of vulnerability is CVE-2019-10864?
CVE-2019-10864 is an XSS (Cross-Site Scripting) vulnerability that allows script injection via the Referer header.
5
Can CVE-2019-10864 be exploited remotely?
Yes, CVE-2019-10864 can be exploited remotely by an attacker sending crafted requests.