The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'burst_total_pageviews_count' custom meta field in all versions up to, and including, 1.5.6.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note that this exploit only functions if the victim has the 'Show Toolbar when viewing site' option enabled in their profile.
We have discovered 7,175 live websites that are affected by CVE-2024-1894.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 7,175 live websites (9.17% of Burst Statistics install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 35 versions ( 79.55% of all versions) |
![]() | 1,771 websites |
![]() | 1,274 websites |
![]() | 644 websites |
![]() | 372 websites |
![]() | 306 websites |
![]() | 234 websites |
![]() | 202 websites |
![]() | 199 websites |
![]() | 198 websites |
![]() | 180 websites |
.com | 2,629 websites |
.de | 715 websites |
.nl | 378 websites |
.fr | 276 websites |
.com.br | 274 websites |
.org | 271 websites |
.co.uk | 194 websites |
.it | 171 websites |
.pl | 142 websites |
.net | 138 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*******.de | ![]() | ***,*** | |
**********.net | ![]() | ***,*** | |
***********.com | ![]() | ***,*** | |
******.org | ![]() | ***,*** | |
***************.com | ![]() | ***,*** | |
*********.fr | ![]() | ***,*** | |
*********.com | ![]() | ***,*** | |
***********.com | ![]() | ***,*** | |
********.com | ![]() | ***,*** | |
***************.com | ![]() | ***,*** |
FAQ