NewStatPress < 1.4.5 - Unauthenticated Stored Cross-Site Scripting
high
The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page...
- CVSS:
- 7.2
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Aug 4, 2026
CVE-2026-14845 on NVD →
NewStatPress [newstatpress] <= 1.4.3 (unfixed)
unknown
[en] The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode function in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wit...
- Affected:
- up to 1.4.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 12, 2025
CVE-2025-13747 on NVD →
NewStatPress <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode function in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with con...
- CVSS:
- 6.4
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Dec 11, 2025
CVE-2025-13747 on NVD →
NewStatPress [newstatpress] < 1.3.6
unknown
[en] The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Feb 14, 2022
CVE-2022-0206 on NVD →
NewStatPress <= 1.3.5 - Reflected Cross-Site Scripting
medium
The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
- CVSS:
- 6.1
- Affected:
- up to 1.3.6
- Fixed in:
- 1.3.6
- Disclosed:
- Jan 13, 2022
CVE-2022-0206 on NVD →
NewStatPress [newstatpress] < 1.2.5
unknown
[en] The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Aug 22, 2019
CVE-2017-18575 on NVD →
NewStatPress [newstatpress] < 1.0.4
unknown
[en] The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- Aug 14, 2019
CVE-2015-9314 on NVD →
NewStatPress [newstatpress] < 1.0.1
unknown
[en] The newstatpress plugin before 1.0.1 for WordPress has SQL injection.
- Affected:
- up to 1.0.1
- Fixed in:
- 1.0.1
- Disclosed:
- Aug 14, 2019
CVE-2015-9315 on NVD →
NewStatPress [newstatpress] < 1.0.6
unknown
[en] The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Aug 14, 2019
CVE-2015-9312 on NVD →
NewStatPress [newstatpress] < 1.0.7
unknown
[en] The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.7
- Disclosed:
- Aug 14, 2019
CVE-2015-9311 on NVD →
NewStatPress [newstatpress] < 1.0.6
unknown
[en] The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Aug 14, 2019
CVE-2015-9313 on NVD →
NewStatPress < 1.2.5 - Unauthenticated Stored Cross-Site Scripting
high
The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wh...
- CVSS:
- 7.2
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Mar 1, 2017
CVE-2017-18575 on NVD →
NewStatPress [newstatpress] < 1.2.5
unknown
WordPress Plugin NewStatPress 1.2.4 has a persistent Cross-Site Scripting (XSS) vulnerability discovered on Summer Of Pwnage event
Update plugin to the latest version (at least 1.2.5)
- Affected:
- up to 1.2.5
- Fixed in:
- 1.2.5
- Disclosed:
- Mar 1, 2017
NewStatPress < 1.0.6 - SQL Injection
critical
The newstatpress plugin before 1.0.6 for WordPress has SQL injection related to an IMG element.
- CVSS:
- 9.8
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jul 7, 2015
CVE-2015-9313 on NVD →
NewStatPress < 1.0.6 - Reflected Cross-Site Scripting
medium
The NewStatPress plugin before 1.0.6 for WordPress has XSS related to an IMG element.
- CVSS:
- 6.1
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jul 7, 2015
CVE-2015-9312 on NVD →
NewStatPress [newstatpress] < 1.0.6
unknown
This plugin is prone to an SQL injection vulnerability. It allows attackers to inject arbitrary SQL commands.
Upgrade this plugin.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jul 7, 2015
NewStatPress [newstatpress] < 1.0.6
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update the plugin.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Jul 7, 2015
NewStatPress <= 1.0.3 - Stored Cross-Site Scripting
high
The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Referer header in versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wh...
- CVSS:
- 7.2
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.4
- Disclosed:
- Jun 30, 2015
CVE-2015-9314 on NVD →
NewStatPress [newstatpress] < 1.0.4
unknown
Because of this vulnerability, the attackers can inject arbitrary web script or HTML.
Update this plugin.
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- Jun 30, 2015
NewStatPress <= 1.0.6 - Reflected Cross-Site Scripting
medium
The NewStatPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'limitquery' parameter in versions up to, and including,1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...
- CVSS:
- 6.1
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.7
- Disclosed:
- Jun 25, 2015
CVE-2015-9311 on NVD →
NewStatPress <= 1.0.0 - SQL Injection
critical
The NewStatPress plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 1.0.0 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL qu...
- CVSS:
- 9.8
- Affected:
- up to 1.0.0
- Fixed in:
- 1.0.1
- Disclosed:
- Jun 8, 2015
CVE-2015-9315 on NVD →
NewStatPress [newstatpress] < 0.9.9
unknown
[en] SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.
- Affected:
- up to 0.9.9
- Fixed in:
- 0.9.9
- Disclosed:
- May 27, 2015
CVE-2015-4062 on NVD →
NewStatPress [newstatpress] < 0.9.9
unknown
[en] Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.
- Affected:
- up to 0.9.9
- Fixed in:
- 0.9.9
- Disclosed:
- May 27, 2015
CVE-2015-4063 on NVD →
NewStatPress <= 0.9.8 - Authenticated SQL Injection
high
SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.
- CVSS:
- 8.8
- Affected:
- up to 0.9.8
- Fixed in:
- 0.9.9
- Disclosed:
- May 25, 2015
CVE-2015-4062 on NVD →
NewStatPress <= 0.9.8 - Authenticated Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.
- CVSS:
- 5.4
- Affected:
- up to 0.9.8
- Fixed in:
- 0.9.9
- Disclosed:
- May 25, 2015
CVE-2015-4063 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database