plugin

Firestats Vulnerabilities

7 known security issues reported for the Firestats WordPress plugin. Most recent disclosed Jul 9, 2010.

2 critical

Running Firestats on your site? Check whether your installed version is affected.

Scan your site free

Firestats [firestats] < 1.6.6

unknown

This Firestats plugin is prone to remote file-include vulnerability. It fails to clean user data sufficiently. The attacker may compromise the application and the other attacks are possible.

Affected:
up to 1.6.6
Fixed in:
1.6.6
Disclosed:
Jul 9, 2010

Firestats [firestats] <= 1.0.2

unknown

FireStats plugin is prone to multiple cross-site scripting vulnerabilities and an authentication BYPASS vulnerabilities. An attacker may gain unauthorized access to the affected application and execute arbitrary script code in the context of the affected site. In that way the attacker can steal cookie-based authentica...

Affected:
up to 1.0.2
Fixed in:
1.0.2
Disclosed:
Nov 24, 2009

FireStats <1.6.2 - SQL Injection

critical

SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS:
10
Affected:
up to 1.6.2
Fixed in:
1.6.2
Disclosed:
Jun 22, 2009

CVE-2009-2144 on NVD →

Firestats [firestats] < 1.6.2 (closed)

unknown

[en] PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter.

Affected:
up to 1.6.2
Fixed in:
1.6.2
Disclosed:
Jun 22, 2009

CVE-2009-2143 on NVD →

Firestats [firestats] < 1.6.2 (closed)

unknown

[en] SQL injection vulnerability in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

Affected:
up to 1.6.2
Fixed in:
1.6.2
Disclosed:
Jun 22, 2009

CVE-2009-2144 on NVD →

FireStats < 1.6.2 - Remote File Inclusion

critical

PHP remote file inclusion vulnerability in firestats-wordpress.php in the FireStats plugin before 1.6.2-stable for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the fs_javascript parameter.

CVSS:
9.8
Affected:
up to 1.6.2
Fixed in:
1.6.2
Disclosed:
Jun 12, 2009

CVE-2009-2143 on NVD →

Firestats [firestats] < 100 (unfixed + closed)

unknown

The firestats WordPress plugin was affected by a Remote Configuration File Download security vulnerability.

Affected:
up to 100
Fix:
No patched version reported

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database