rootpwn

high · CVSS v3 7.1 · EPSS 0.00146

CVE-2026-97276

WP Statistics plugin for WordPress contains a reflected XSS flaw that can be triggered via crafted URLs, allowing attackers to inject malici

Overview

WP Statistics plugin for WordPress contains a reflected XSS flaw that can be triggered via crafted URLs, allowing attackers to inject malicious scripts into pages viewed by site visitors. The vulnerability exists in all releases up to 14.16.14 and can lead to data theft or defacement.

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics allows Reflected XSS.This issue affects WP Statistics: from n/a through 14.16.14.

Impact

The flaw can compromise confidentiality by enabling attackers to steal session cookies or other sensitive data, and can undermine integrity by allowing unauthorized content injection. Site administrators and visitors are directly impacted, as any user who loads a crafted page can be affected.

Remediation

Update WP Statistics to version 14.16.15 or later. If an update is not immediately possible, disable the plugin or restrict its usage to trusted users. Implement a Content Security Policy that blocks inline scripts and disallows execution of untrusted code. Monitor logs for suspicious URL patterns and apply input sanitization on any custom query parameters.

Risk context

The vulnerability is rated high severity (CVSS 7.1) but has a low EPSS score of 0.00146, indicating a low likelihood of exploitation yet still requiring timely mitigation.

Affected products

  • VeronaLabs WP Statistics
  • WordPress WP Statistics plugin

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.1
CVSS v4
—
EPSS
0.00146

XSS WP Statistics WordPress Reflected XSS High Severity Input Validation Web Vulnerability

← All CVEs