CVE-2022-25307: WP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via platform
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-25307?
CVE-2022-25307 is a vulnerability in the WP Statistics WordPress plugin that allows attackers to inject arbitrary web scripts onto several pages of a website.
What is the severity of CVE-2022-25307?
CVE-2022-25307 has a severity rating of 6.1, which is considered high.
How does CVE-2022-25307 affect the WP Statistics WordPress plugin?
CVE-2022-25307 affects the WP Statistics WordPress plugin by allowing attackers to exploit insufficient escaping and sanitization of the platform parameter in the ~/includes/class-wp-statistics-hits.php file.
Which version of the WP Statistics WordPress plugin is affected by CVE-2022-25307?
Version 13.1.5 of the WP Statistics WordPress plugin is affected by CVE-2022-25307.
How can I fix CVE-2022-25307?
To fix CVE-2022-25307, update the WP Statistics WordPress plugin to a version that has been patched for the vulnerability.