Known CVE
NewStatPress <=1.0.4 - Cross-Site Scripting
WordPress NewStatPress plugin through 1.0.4 contains a cross-site scripting vulnerability. The plugin utilizes, on lines 28 and 31 of the file "includes/nsp_search.php", several variables from the $_GET scope without sanitation. While WordPress automatically escapes quotes on this scope, the outputs on these lines are outside of quotes, and as such can be utilized to initiate a cross-site scripting attack.
CVE-2015-9312
Medium2015CVSS 6.1CWE-79
cve2015 · xss · authenticated · wp · newstatpress · wpscan · wordpress · wp-plugin
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website