WordPress 插件 WP Statistics——一款简单、注重隐私保护的 Google Analytics 替代品,在 14.16.8 及以下所有版本中,存在存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞源于对 参数的输入净化和输出转义不充分,导致未经验证的攻击者能够将任意 Web 脚本注入到网页中,当用户访问被注入的页面时,脚本便会自动执行。 攻击者无需认证即可通过公开的 REST 接口植入恶意负载。这是因为该接口所需的签名信息在公开主页上可见,且一个经过
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| veronalabs | WP Statistics – Simple, privacy-friendly Google Analytics alternative | ≤ 14.16.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| veronalabs | WP Statistics – Simple, privacy-friendly Google Analytics alternative | 0 ~ 14.16.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No comments yet