1 results (0.003 seconds)

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 0

26 Nov 2014 — Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Manually enter your UA code" (manual_ua_code_field) field in the General Settings. Vulnerabilidad de XSS en el plugin Google Analytics by Yoast (google-analytics-for-wordpress) anterior a 5.1.3 para WordPress permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a travé... • http://www.securityfocus.com/bid/71330 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •