cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2024-8738,https://securityvulnerability.io/vulnerability/CVE-2024-8738,Unauthenticated Cross-Site Scripting Vulnerability in Seriously Simple Stats Plugin,"The Seriously Simple Stats plugin for WordPress contains a vulnerability that exposes it to reflected cross-site scripting due to the improper use of add_query_arg without adequate escaping on URLs. This flaw affects all versions up to and including 1.6.0. As a result, unauthenticated attackers may inject malicious web scripts into linked pages, which can execute if a user is misled into clicking a compromised link. This vulnerability highlights the importance of adhering to best practices for input handling and sanitization within web applications.",Wordpress,Seriously Simple Stats,6.1,MEDIUM,0.0005200000014156103,false,,false,false,false,,,false,false,,2024-09-24T01:56:48.112Z,0