high · CVSS v3 7.1 · EPSS 0.00146
CVE-2026-97276
WP Statistics plugin for WordPress contains a reflected XSS flaw that can be triggered via crafted URLs, allowing attackers to inject malici
Overview
WP Statistics plugin for WordPress contains a reflected XSS flaw that can be triggered via crafted URLs, allowing attackers to inject malicious scripts into pages viewed by site visitors. The vulnerability exists in all releases up to 14.16.14 and can lead to data theft or defacement.
Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics allows Reflected XSS.This issue affects WP Statistics: from n/a through 14.16.14.
Impact
The flaw can compromise confidentiality by enabling attackers to steal session cookies or other sensitive data, and can undermine integrity by allowing unauthorized content injection. Site administrators and visitors are directly impacted, as any user who loads a crafted page can be affected.
Remediation
Update WP Statistics to version 14.16.15 or later. If an update is not immediately possible, disable the plugin or restrict its usage to trusted users. Implement a Content Security Policy that blocks inline scripts and disallows execution of untrusted code. Monitor logs for suspicious URL patterns and apply input sanitization on any custom query parameters.
Risk context
The vulnerability is rated high severity (CVSS 7.1) but has a low EPSS score of 0.00146, indicating a low likelihood of exploitation yet still requiring timely mitigation.
Affected products
- VeronaLabs WP Statistics
- WordPress WP Statistics plugin
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.1
- CVSS v4
- —
- EPSS
- 0.00146