The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against logged in admin viewing the logs
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 09 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-04-09T19:23:59.359Z

Reserved: 2022-12-06T15:29:32.980Z

Link: CVE-2022-4310

cve-icon Vulnrichment

Updated: 2024-08-03T01:34:50.117Z

cve-icon NVD

Status : Modified

Published: 2023-01-09T23:15:27.573

Modified: 2025-04-09T20:15:24.037

Link: CVE-2022-4310

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.