The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mitchelllevy
Mitchelllevy ahathat |
|
Weaknesses | CWE-79 | |
CPEs | cpe:2.3:a:mitchelllevy:ahathat:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Mitchelllevy
Mitchelllevy ahathat |
Mon, 06 Jan 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 02 Jan 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers | |
Title | AHAthat Plugin <= 1.6 - Reflected XSS via REQUEST_URI | |
References |
|

Status: PUBLISHED
Assigner: WPScan
Published: 2025-01-02T06:00:13.479Z
Updated: 2025-01-06T20:26:50.598Z
Reserved: 2024-12-12T22:04:10.012Z
Link: CVE-2024-12595

Updated: 2025-01-06T20:26:23.443Z

Status : Analyzed
Published: 2025-01-02T06:15:07.983
Modified: 2025-06-12T17:04:11.687
Link: CVE-2024-12595

No data.