#VU19035 Cross-site request forgery in Visitors Traffic Real Time Statistics - CVE-2019-15832,CVE-2019-15831
Published: July 8, 2019 / Updated: September 4, 2019
Visitors Traffic Real Time Statistics
wp-buy
Description
The vulnerability allows a remote attacker to perform cross-site request forgery attacks.
The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can craft an AJAX request, which lets blog administrators alter plugin settings.
This vulnerability leads to a Stored XSS and SQL Injection.