Medium severity6.1NVD Advisory· Published Dec 20, 2017· Updated May 13, 2026
CVE-2011-4955
CVE-2011-4955
Description
Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) p parameters to index.php.
Affected products
2cpe:2.3:a:bsuite_project:bsuite:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:bsuite_project:bsuite:*:*:*:*:*:wordpress:*:*range: <=4.0.7
- cpe:2.3:a:bsuite_project:bsuite:5.0:a2:*:*:*:wordpress:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- wordpress.org/support/topic/plugin-bsuite-xss-security-vulnerability-in-407nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2012/04/16/3nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2012/04/16/8nvdMailing ListThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/68602nvdThird Party AdvisoryVDB Entry
- plugins.trac.wordpress.org/changesetnvdBroken Link
- secunia.com/advisories/45234nvdPermissions Required
News mentions
0No linked articles in our index yet.