CVE-2015-6238
Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3)…
Does this matter?
Lower severity and a low EPSS score (2.67%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3) ga_downloads_prefix, (4) ga_downloads, or (5) ga_outbound_prefix parameter in the google-analyticator page to wp-admin/admin.php.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.67% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- sumome/google analyticator
- Source
- cve@mitre.org
References
- https://wordpress.org/plugins/google-analyticator/changelog/Patch
- https://wpvulndb.com/vulnerabilities/8159
- https://www.netsparker.com/cve-2015-6238-multiple-xss-vulnerabilities-in-google-analyticator/Exploit
- https://wordpress.org/plugins/google-analyticator/changelog/Patch
- https://wpvulndb.com/vulnerabilities/8159
- https://www.netsparker.com/cve-2015-6238-multiple-xss-vulnerabilities-in-google-analyticator/Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.