CVE-2022-4310

Publication date

2023-01-09 22:13:26

Family

WPScan

State

PUBLISHED

Description

The Slimstat Analytics WordPress plugin before 4.9.3 does not sanitise and escape the URI when logging requests, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against logged in admin viewing the logs