plugin

Newstatpress Vulnerabilities

25 known security issues reported for the Newstatpress WordPress plugin. Most recent disclosed Aug 4, 2026.

2 critical 4 high 5 medium

Running Newstatpress on your site? Check whether your installed version is affected.

Scan your site free

NewStatPress < 1.4.5 - Unauthenticated Stored Cross-Site Scripting

high

The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 1.4.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page...

CVSS:
7.2
Affected:
up to 1.4.5
Fixed in:
1.4.5
Disclosed:
Aug 4, 2026

CVE-2026-14845 on NVD →

NewStatPress [newstatpress] <= 1.4.3 (unfixed)

unknown

[en] The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode function in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, wit...

Affected:
up to 1.4.3
Fix:
No patched version reported
Disclosed:
Dec 12, 2025

CVE-2025-13747 on NVD →

NewStatPress <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a regex bypass in nsp_shortcode function in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with con...

CVSS:
6.4
Affected:
up to 1.4.3
Fixed in:
1.4.4
Disclosed:
Dec 11, 2025

CVE-2025-13747 on NVD →

NewStatPress [newstatpress] < 1.3.6

unknown

[en] The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

Affected:
up to 1.3.6
Fixed in:
1.3.6
Disclosed:
Feb 14, 2022

CVE-2022-0206 on NVD →

NewStatPress <= 1.3.5 - Reflected Cross-Site Scripting

medium

The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues

CVSS:
6.1
Affected:
up to 1.3.6
Fixed in:
1.3.6
Disclosed:
Jan 13, 2022

CVE-2022-0206 on NVD →

NewStatPress [newstatpress] < 1.2.5

unknown

[en] The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.

Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Aug 22, 2019

CVE-2017-18575 on NVD →

NewStatPress [newstatpress] < 1.0.4

unknown

[en] The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Aug 14, 2019

CVE-2015-9314 on NVD →

NewStatPress [newstatpress] < 1.0.1

unknown

[en] The newstatpress plugin before 1.0.1 for WordPress has SQL injection.

Affected:
up to 1.0.1
Fixed in:
1.0.1
Disclosed:
Aug 14, 2019

CVE-2015-9315 on NVD →

NewStatPress [newstatpress] < 1.0.6

unknown

[en] The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Aug 14, 2019

CVE-2015-9312 on NVD →

NewStatPress [newstatpress] < 1.0.7

unknown

[en] The newstatpress plugin before 1.0.6 for WordPress has reflected XSS.

Affected:
up to 1.0.7
Fixed in:
1.0.7
Disclosed:
Aug 14, 2019

CVE-2015-9311 on NVD →

NewStatPress [newstatpress] < 1.0.6

unknown

[en] The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Aug 14, 2019

CVE-2015-9313 on NVD →

NewStatPress < 1.2.5 - Unauthenticated Stored Cross-Site Scripting

high

The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wh...

CVSS:
7.2
Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Mar 1, 2017

CVE-2017-18575 on NVD →

NewStatPress [newstatpress] < 1.2.5

unknown

WordPress Plugin NewStatPress 1.2.4 has a persistent Cross-Site Scripting (XSS) vulnerability discovered on Summer Of Pwnage event Update plugin to the latest version (at least 1.2.5)

Affected:
up to 1.2.5
Fixed in:
1.2.5
Disclosed:
Mar 1, 2017

NewStatPress < 1.0.6 - SQL Injection

critical

The newstatpress plugin before 1.0.6 for WordPress has SQL injection related to an IMG element.

CVSS:
9.8
Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Jul 7, 2015

CVE-2015-9313 on NVD →

NewStatPress < 1.0.6 - Reflected Cross-Site Scripting

medium

The NewStatPress plugin before 1.0.6 for WordPress has XSS related to an IMG element.

CVSS:
6.1
Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Jul 7, 2015

CVE-2015-9312 on NVD →

NewStatPress [newstatpress] < 1.0.6

unknown

This plugin is prone to an SQL injection vulnerability. It allows attackers to inject arbitrary SQL commands. Upgrade this plugin.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Jul 7, 2015

NewStatPress [newstatpress] < 1.0.6

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update the plugin.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Jul 7, 2015

NewStatPress <= 1.0.3 - Stored Cross-Site Scripting

high

The NewStatPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Referer header in versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute wh...

CVSS:
7.2
Affected:
up to 1.0.3
Fixed in:
1.0.4
Disclosed:
Jun 30, 2015

CVE-2015-9314 on NVD →

NewStatPress [newstatpress] < 1.0.4

unknown

Because of this vulnerability, the attackers can inject arbitrary web script or HTML. Update this plugin.

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Jun 30, 2015

NewStatPress <= 1.0.6 - Reflected Cross-Site Scripting

medium

The NewStatPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'limitquery' parameter in versions up to, and including,1.8.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execu...

CVSS:
6.1
Affected:
up to 1.0.6
Fixed in:
1.0.7
Disclosed:
Jun 25, 2015

CVE-2015-9311 on NVD →

NewStatPress <= 1.0.0 - SQL Injection

critical

The NewStatPress plugin for WordPress is vulnerable to generic SQL Injection in versions up to, and including, 1.0.0 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL qu...

CVSS:
9.8
Affected:
up to 1.0.0
Fixed in:
1.0.1
Disclosed:
Jun 8, 2015

CVE-2015-9315 on NVD →

NewStatPress [newstatpress] < 0.9.9

unknown

[en] SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.

Affected:
up to 0.9.9
Fixed in:
0.9.9
Disclosed:
May 27, 2015

CVE-2015-4062 on NVD →

NewStatPress [newstatpress] < 0.9.9

unknown

[en] Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.

Affected:
up to 0.9.9
Fixed in:
0.9.9
Disclosed:
May 27, 2015

CVE-2015-4063 on NVD →

NewStatPress <= 0.9.8 - Authenticated SQL Injection

high

SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.

CVSS:
8.8
Affected:
up to 0.9.8
Fixed in:
0.9.9
Disclosed:
May 25, 2015

CVE-2015-4062 on NVD →

NewStatPress <= 0.9.8 - Authenticated Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.

CVSS:
5.4
Affected:
up to 0.9.8
Fixed in:
0.9.9
Disclosed:
May 25, 2015

CVE-2015-4063 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database