The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers before outputting them back in an admin page, allowing unauthenticated users to perform Stored XSS attacks against logged in admins
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-11-27T16:22:01.293Z

Updated: 2023-11-27T16:22:01.293Z

Reserved: 2023-10-19T11:49:37.990Z


Link: CVE-2023-5653

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-27T17:15:09.230

Modified: 2023-12-04T14:53:32.297


Link: CVE-2023-5653

JSON object: View

cve-icon Redhat Information

No data.

CWE