plugin

Wassup Vulnerabilities

11 known security issues reported for the Wassup WordPress plugin. Most recent disclosed Nov 27, 2023.

1 critical 1 high 3 medium

Running Wassup on your site? Check whether your installed version is affected.

Scan your site free

WassUp Real Time Analytics [wassup] <= 1.9.4.5 (unfixed + closed)

unknown

[en] The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers before outputting them back in an admin page, allowing unauthenticated users to perform Stored XSS attacks against logged in admins

Affected:
up to 1.9.4.5
Fix:
No patched version reported
Disclosed:
Nov 27, 2023

CVE-2023-5653 on NVD →

WassUp Real Time Analytics <= 1.9.4.5 - Unauthenticated Stored Cross-Site Scripting via IP

high

The WassUp Real Time Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via spoofed IP Addresses in all versions up to, and including, 1.9.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
7.2
Affected:
up to 1.9.4.5
Fix:
No patched version reported
Disclosed:
Nov 6, 2023

CVE-2023-5653 on NVD →

WassUp Real Time Analytics <= 1.9.4.4 - Cross-Site Scripting

medium

The WassUp Real Time Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.9.4.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute wh...

CVSS:
6.1
Affected:
up to 1.9.4.4
Fixed in:
1.9.4.5
Disclosed:
Jul 1, 2020

WassUp Real Time Analytics [wassup] < 1.9.4.5 (closed)

unknown

The WassUp Real Time Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.9.4.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute wh...

Affected:
up to 1.9.4.5
Fixed in:
1.9.4.5
Disclosed:
Jul 1, 2020

WassUp Real Time Analytics [wassup] < 1.9.1 (closed)

unknown

[en] The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a different vulnerability than CVE-2012-2633.

Affected:
up to 1.9.1
Fixed in:
1.9.1
Disclosed:
Aug 22, 2019

CVE-2016-10919 on NVD →

WassUp Real Time Analytics < 1.9.1 - Cross-Site Scripting

medium

The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a different vulnerability than CVE-2012-2633.

CVSS:
6.1
Affected:
up to 1.9.1
Fixed in:
1.9.1
Disclosed:
Nov 8, 2016

CVE-2016-10919 on NVD →

WassUp Real Time Analytics [wassup] < 1.9.1 (closed)

unknown

Because of this vulnerability attackers can inject malicious JavaScript code into the application, which will execute within the browser of any user who views the Activity Log, in general WP admin. Update the plugin.

Affected:
up to 1.9.1
Fixed in:
1.9.1
Disclosed:
Nov 8, 2016

WassUp Real Time Analytics [wassup] < 1.8.3.1 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in wassup.php in the WassUp plugin before 1.8.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

Affected:
up to 1.8.3.1
Fixed in:
1.8.3.1
Disclosed:
Jun 15, 2012

CVE-2012-2633 on NVD →

WassUp Real Time Analytics < 1.8.3.1 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in wassup.php in the WassUp plugin before 1.8.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

CVSS:
6.1
Affected:
up to 1.8.3.1
Fixed in:
1.8.3.1
Disclosed:
Jun 6, 2012

CVE-2012-2633 on NVD →

WassUp Real Time Analytics [wassup] >= 1.4 - <= 1.4.3 (closed)

unknown

[en] Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.

Affected:
1.4 – 1.4.3
Fixed in:
1.4.3
Disclosed:
Jan 31, 2008

CVE-2008-0520 on NVD →

WassUp Real Time Analytics 1.4 - 1.4.3 - SQL Injection

critical

Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.

CVSS:
9.8
Affected:
1.4 – 1.4.3
Fixed in:
1.4.4
Disclosed:
Jan 30, 2008

CVE-2008-0520 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database