CVE-2015-10001

The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:wp-stats_project:wp-stats:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2021-11-01 09:15

Updated : 2024-02-28 18:48


NVD link : CVE-2015-10001

Mitre link : CVE-2015-10001

CVE.ORG link : CVE-2015-10001


JSON object : View

Products Affected

wp-stats_project

  • wp-stats
CWE
CWE-352

Cross-Site Request Forgery (CSRF)