CVE-2024-2194: wp-statistics
## The Exploit An unauthenticated attacker can inject arbitrary JavaScript into WordPress admin pages by crafting a malicious URL that WP Statistics processes and reflects without proper escaping. ```http GET /wp-admin/admin.php?page=wps_...
Read article →