Vulnerabilities
Vulnerable Software
The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
CVSS Score
6.1
EPSS Score
0.042
Published
2022-02-14
The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-08-22
The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-08-14
The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
CVSS Score
6.1
EPSS Score
0.042
Published
2019-08-14
The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-08-14
The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-08-14
The newstatpress plugin before 1.0.1 for WordPress has SQL injection.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-08-14


Contact Us

Shodan ® - All rights reserved