WordPress Plugin Vulnerabilities

Universal Analytics <= 1.3.0 - Authenticated Cross-Site Scripting (XSS)

Description

"A subscriber could update the plugins settings via the URL or AJAX. The settings were not sanitized before saving to the database and not escaped before outputted on the front end."

Affects Plugins

Fixed in 1.3.1

References

Classification

Type
XSS
CWE

Miscellaneous

Submitter
Ulrich
Submitter twitter
Verified
No

Timeline

Publicly Published
2016-02-04 (about 10 years ago)
Added
2016-02-06 (about 10 years ago)
Last Updated
2020-09-22 (about 5 years ago)

Other