VULNERABILITY INTELLIGENCE
CVE-2011-0641
CVSS score4.3 MEDIUM
EPSS probability1.83%
CISA KEVNot currently listed
Published2011-01-25
Last modified2026-06-16
Description
Multiple cross-site scripting (XSS) vulnerabilities in wp-admin/admin.php in the StatPressCN plugin 1.9.0 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) what1, (2) what2, (3) what3, (4) what4, and (5) what5 parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.