CyberRota Analysis
AI-GeneratedThe NewStatPress WordPress plugin prior to version 1.4.5 is vulnerable due to insufficient sanitization and escaping of data from unauthenticated visitor requests, potentially enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to inject malicious scripts that execute when users interact with the affected widget, compromising user security. WordPress site administrators using this plugin should prioritize updating to version 1.4.5 or later to mitigate the risk.
Original NVD Description
The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in one of its widgets, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against users viewing the affected widget.