CVE-2024-2194
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Mar 13, 2024
Summary
CVE-2024-2194 is a Stored Cross-Site Scripting (XSS) vulnerability affecting the WP Statistics plugin for WordPress. Affecting versions up to and including 14.5, this issue arises due to inadequate input sanitization and output escaping in the plugin's URL search parameter. Unauthenticated assailants can take advantage of this weakness to inject malicious web scripts into pages. Execution of these scripts occurs whenever an unsuspecting user accesses an injected page, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share