The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
History

Thu, 12 Jun 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Pixeljar
Pixeljar geocache Stat Bar Widget
Weaknesses CWE-79
CPEs cpe:2.3:a:pixeljar:geocache_stat_bar_widget:*:*:*:*:*:wordpress:*:*
Vendors & Products Pixeljar
Pixeljar geocache Stat Bar Widget

Tue, 20 May 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Geocache Stat Bar Widget WordPress plugin through 0.911 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Title Geocache Stat Bar Widget <= 0.911 - Admin+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:06:48.506Z

Updated: 2025-05-20T19:36:05.227Z

Reserved: 2024-11-15T17:43:05.895Z

Link: CVE-2024-11266

cve-icon Vulnrichment

Updated: 2025-05-19T20:36:26.343Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:34.553

Modified: 2025-06-12T15:17:29.410

Link: CVE-2024-11266

cve-icon Redhat

No data.