Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57946 | The WassUp Real Time Analytics WordPress plugin through 1.9.4.5 does not escape IP address provided via some headers before outputting them back in an admin page, allowing unauthenticated users to perform Stored XSS attacks against logged in admins |
No history.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-02T08:07:32.554Z
Reserved: 2023-10-19T11:49:37.990Z
Link: CVE-2023-5653
No data.
Status : Modified
Published: 2023-11-27T17:15:09.230
Modified: 2026-06-17T06:49:01.103
Link: CVE-2023-5653
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
EUVD