WassUp Real Time Analytics [wassup] <= 1.9.4.5 (unfixed + closed)
unknown
[en] The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers before outputting them back in an admin page, allowing unauthenticated users to perform Stored XSS attacks against logged in admins
- Affected:
- up to 1.9.4.5
- Fix:
- No patched version reported
- Disclosed:
- Nov 27, 2023
CVE-2023-5653 on NVD →
WassUp Real Time Analytics <= 1.9.4.5 - Unauthenticated Stored Cross-Site Scripting via IP
high
The WassUp Real Time Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via spoofed IP Addresses in all versions up to, and including, 1.9.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...
- CVSS:
- 7.2
- Affected:
- up to 1.9.4.5
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2023
CVE-2023-5653 on NVD →
WassUp Real Time Analytics <= 1.9.4.4 - Cross-Site Scripting
medium
The WassUp Real Time Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.9.4.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute wh...
- CVSS:
- 6.1
- Affected:
- up to 1.9.4.4
- Fixed in:
- 1.9.4.5
- Disclosed:
- Jul 1, 2020
WassUp Real Time Analytics [wassup] < 1.9.4.5 (closed)
unknown
The WassUp Real Time Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.9.4.4 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute wh...
- Affected:
- up to 1.9.4.5
- Fixed in:
- 1.9.4.5
- Disclosed:
- Jul 1, 2020
WassUp Real Time Analytics [wassup] < 1.9.1 (closed)
unknown
[en] The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a different vulnerability than CVE-2012-2633.
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.1
- Disclosed:
- Aug 22, 2019
CVE-2016-10919 on NVD →
WassUp Real Time Analytics < 1.9.1 - Cross-Site Scripting
medium
The wassup plugin before 1.9.1 for WordPress has XSS via the Top stats widget or the wassupURI::add_siteurl method, a different vulnerability than CVE-2012-2633.
- CVSS:
- 6.1
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.1
- Disclosed:
- Nov 8, 2016
CVE-2016-10919 on NVD →
WassUp Real Time Analytics [wassup] < 1.9.1 (closed)
unknown
Because of this vulnerability attackers can inject malicious JavaScript code into the application, which will execute within the browser of any user who views the Activity Log, in general WP admin.
Update the plugin.
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.1
- Disclosed:
- Nov 8, 2016
WassUp Real Time Analytics [wassup] < 1.8.3.1 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in wassup.php in the WassUp plugin before 1.8.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
- Affected:
- up to 1.8.3.1
- Fixed in:
- 1.8.3.1
- Disclosed:
- Jun 15, 2012
CVE-2012-2633 on NVD →
WassUp Real Time Analytics < 1.8.3.1 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in wassup.php in the WassUp plugin before 1.8.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.
- CVSS:
- 6.1
- Affected:
- up to 1.8.3.1
- Fixed in:
- 1.8.3.1
- Disclosed:
- Jun 6, 2012
CVE-2012-2633 on NVD →
WassUp Real Time Analytics [wassup] >= 1.4 - <= 1.4.3 (closed)
unknown
[en] Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.
- Affected:
- 1.4 – 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Jan 31, 2008
CVE-2008-0520 on NVD →
WassUp Real Time Analytics 1.4 - 1.4.3 - SQL Injection
critical
Multiple SQL injection vulnerabilities in main.php in the WassUp plugin 1.4 through 1.4.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) from_date or (2) to_date parameter to spy.php.
- CVSS:
- 9.8
- Affected:
- 1.4 – 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Jan 30, 2008
CVE-2008-0520 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database