plugin

Wordpress Feed Statistics Vulnerabilities

2 known security issues reported for the Wordpress Feed Statistics WordPress plugin. Most recent disclosed Oct 11, 2023.

2 medium

Running Wordpress Feed Statistics on your site? Check whether your installed version is affected.

Scan your site free

Feed Statistics <= 4.1 - Cross-Site Request Forgery via init

medium

The Feed Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1. This is due to missing or incorrect nonce validation on the init function. This makes it possible for unauthenticated attackers to modify plugin settings via a forged request granted they can tric...

CVSS:
4.3
Affected:
up to 4.1
Fix:
No patched version reported
Disclosed:
Oct 11, 2023

CVE-2023-45605 on NVD →

Feed Statistics < 4.0 - Open Redirect

medium

The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.

CVSS:
6.1
Affected:
up to 4.0
Fixed in:
4.0
Disclosed:
Aug 7, 2014

CVE-2018-17074 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database