Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-66617
HistoryMar 16, 2022 - 12:00 a.m.

WordPress Simple Tracking plugin cross-site scripting vulnerability

2022-03-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
18
wordpress
simple tracking plugin
cross-site scripting
vulnerability
attackers
php
blogging platforms

EPSS

0.001

Percentile

24.8%

WordPress is a set of blogging platforms developed by the Wordpress Foundation using the PHP language. WordPress plugin is an application plugin for WordPress. A cross-site scripting vulnerability exists in versions of WordPress Simple Tracking plugin prior to 1.7, which stems from the plugin’s failure to clean and escape its settings, and could be exploited by attackers to perform cross-site scripting attacks. The vulnerability is caused by the plugin’s failure to clean and escape its settings, which can be exploited to perform cross-site scripting attacks.

EPSS

0.001

Percentile

24.8%