Lucene search

K
osvGoogleOSV:CVE-2022-1005
HistoryJun 08, 2022 - 10:15 a.m.

CVE-2022-1005

2022-06-0810:15:09
Google
osv.dev
20
cve-2022-1005
wp statistics
cross-site scripting

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

34.0%

The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode characters

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

34.0%