WP Statistics <= 14.16.8 - Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter
high
The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticate...
- CVSS:
- 7.2
- Affected:
- up to 14.16.8
- Fixed in:
- 14.16.9
- Disclosed:
- Aug 18, 2026
CVE-2026-15780 on NVD →
Statistics <= 14.16.9 - Authenticated (Subscriber+) Information Exposure
medium
The Statistics plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 14.16.9. This is due to missing capability check in the BaseMetabox AJAX handler before returning statistics data. This makes it possible for authenticated attackers, with subscriber-level access and ab...
- CVSS:
- 4.3
- Affected:
- up to 14.16.9
- Fixed in:
- 14.16.10
- Disclosed:
- Aug 3, 2026
CVE-2026-16562 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative <= 14.16.6 - Unauthenticated Stored Cross-Site Scripting
high
The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 14.16.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...
- CVSS:
- 7.2
- Affected:
- up to 14.16.6
- Fixed in:
- 14.16.7
- Disclosed:
- Jun 1, 2026
CVE-2026-48839 on NVD →
WP Statistics <= 14.16.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure and Privacy Audit Manipulation
medium
The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing capability checks on multiple AJAX handlers including `wp_statistics_get_filters`, `wp_statistics_getPrivacyStatus`, `wp_statistics_updatePrivacyStatus`, and `wp_statistics...
- CVSS:
- 6.5
- Affected:
- up to 14.16.4
- Fixed in:
- 14.16.5
- Disclosed:
- Apr 16, 2026
CVE-2026-3488 on NVD →
WP Statistics <= 14.16.4 - Unauthenticated Stored Cross-Site Scripting via 'utm_source' Parameter
high
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and including, 14.16.4. This is due to insufficient input sanitization and output escaping. The plugin's referral parser copies the raw utm_source value into the source_name field wh...
- CVSS:
- 7.2
- Affected:
- up to 14.16.4
- Fixed in:
- 14.16.5
- Disclosed:
- Apr 16, 2026
CVE-2026-5231 on NVD →
WP Statistics <= 14.5.4 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header
high
The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent Header in all versions up to, and including, 14.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...
- CVSS:
- 7.2
- Affected:
- up to 14.15.4
- Fixed in:
- 14.15.5
- Disclosed:
- Sep 26, 2025
CVE-2025-9816 on NVD →
WP Statistics < 14.15.5 - Unauthenticated Stored XSS via User-Agent Header
medium
- Affected:
- up to 14.15.5
- Fixed in:
- 14.15.5
- Disclosed:
- Sep 26, 2025
CVE-2025-9816 on NVD →
WP Statistics <= 14.15 - Missing Authorization
medium
The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 14.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to per...
- CVSS:
- 4.3
- Affected:
- up to 14.15
- Fixed in:
- 14.15.2
- Disclosed:
- Aug 14, 2025
CVE-2025-55716 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.15.2
unknown
[en] Missing Authorization vulnerability in VeronaLabs WP Statistics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Statistics: from n/a through 14.15.
- Affected:
- up to 14.15.2
- Fixed in:
- 14.15.2
- Disclosed:
- Aug 14, 2025
CVE-2025-55716 on NVD →
WP Statistics < 14.15.2 - Missing Authorization
medium
- Affected:
- up to 14.15.2
- Fixed in:
- 14.15.2
- Disclosed:
- Aug 14, 2025
CVE-2025-55716 on NVD →
WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin <= 14.13.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Update
medium
The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'optionUpdater' function in all versions up to, and including, 14.13.3. This makes it possible for authenticated attackers, with Subscri...
- CVSS:
- 5.4
- Affected:
- up to 14.13.3
- Fixed in:
- 14.13.4
- Disclosed:
- Apr 29, 2025
CVE-2025-3953 on NVD →
WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin < 14.13.4 - Subscriber+ Arbitrary Plugin Settings Update
unknown
- Affected:
- up to 14.13.4
- Fixed in:
- 14.13.4
- Disclosed:
- Apr 29, 2025
CVE-2025-3953 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.5.1
unknown
[en] The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- Affected:
- up to 14.5.1
- Fixed in:
- 14.5.1
- Disclosed:
- Mar 13, 2024
CVE-2024-2194 on NVD →
WP Statistics <= 14.5 - Unauthenticated Stored Cross-Site Scripting
high
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will...
- CVSS:
- 7.2
- Affected:
- up to 14.5
- Fixed in:
- 14.5.1
- Disclosed:
- Mar 11, 2024
CVE-2024-2194 on NVD →
WP Statistics < 14.5.1 - Unauthenticated Stored Cross-Site Scripting
high
- Affected:
- up to 14.5.1
- Fixed in:
- 14.5.1
- Disclosed:
- Mar 11, 2024
CVE-2024-2194 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.0
unknown
[en] The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to a...
- Affected:
- up to 14.0
- Fixed in:
- 14.0
- Disclosed:
- Mar 27, 2023
CVE-2023-0955 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.2.11
unknown
[en] SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.
- Affected:
- up to 13.2.11
- Fixed in:
- 13.2.11
- Disclosed:
- Mar 13, 2023
CVE-2022-38074 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.2
unknown
[en] The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing or incorrect nonce validation on the view() function. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins, via a forged r...
- Affected:
- up to 13.1.2
- Fixed in:
- 13.1.2
- Disclosed:
- Mar 7, 2023
CVE-2021-4333 on NVD →
WP Statistics <= 13.2.16 - Authenticated (Admin+) SQL Injection
high
The WP Statistics plugin for WordPress is vulnerable to SQL Injection via the $days_time_list value in versions up to, and including, 13.2.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with...
- CVSS:
- 7.2
- Affected:
- up to 13.2.16
- Fixed in:
- 14.0
- Disclosed:
- Mar 6, 2023
CVE-2023-0955 on NVD →
WP Statistics < 14.0 - Authenticated SQLi
unknown
- Affected:
- up to 14.0
- Fixed in:
- 14.0
- Disclosed:
- Mar 6, 2023
CVE-2023-0955 on NVD →
WP Statistics <= 13.2.10 - Authenticated (Subscriber+) SQL Injection
high
The WP Statistics plugin for WordPress is vulnerable to SQL Injection via the ‘limit’ parameter in versions up to, and including, 13.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for subscriber-level attackers to ap...
- CVSS:
- 8.8
- Affected:
- up to 13.2.10
- Fixed in:
- 13.2.11
- Disclosed:
- Jan 31, 2023
CVE-2022-38074 on NVD →
WP Statistics < 13.2.11 - Subscriber+ SQLi
unknown
- Affected:
- up to 13.2.11
- Fixed in:
- 13.2.11
- Disclosed:
- Jan 31, 2023
CVE-2022-38074 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.2.9
unknown
[en] The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to...
- Affected:
- up to 13.2.9
- Fixed in:
- 13.2.9
- Disclosed:
- Jan 23, 2023
CVE-2022-4230 on NVD →
WP Statistics <= 13.2.8 - Authenticated (Admin+) SQL Injection
high
The WP Statistics plugin for WordPress is vulnerable to SQL Injection via the $search_engine value in versions up to, and including, 13.2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with a...
- CVSS:
- 7.2
- Affected:
- up to 13.2.8
- Fixed in:
- 13.2.9
- Disclosed:
- Dec 27, 2022
CVE-2022-4230 on NVD →
WP Statistics < 13.2.9 - Authenticated SQLi
unknown
- Affected:
- up to 13.2.9
- Fixed in:
- 13.2.9
- Disclosed:
- Dec 27, 2022
CVE-2022-4230 on NVD →
WP Statistics <= 13.2.5 - Authenticated (Subscriber+) SQL Injection
high
The WP Statistics plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘agent’ parameter in versions up to, and including, 13.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated att...
- CVSS:
- 8.8
- Affected:
- up to 13.2.5
- Fixed in:
- 13.2.6
- Disclosed:
- Sep 8, 2022
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.2.6
unknown
The WP Statistics plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘agent’ parameter in versions up to, and including, 13.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated att...
- Affected:
- up to 13.2.6
- Fixed in:
- 13.2.6
- Disclosed:
- Sep 8, 2022
WP Statistics <= 13.2.5 - Information Disclosure
medium
The WP Statistics plugin for WordPress is vulnerable to information disclosure via the Metabox REST API in versions up to, and including, 13.2.5. This allows all authenticated users to access statistics generated by the plugin.
- CVSS:
- 4.3
- Affected:
- 13.2.5 – 13.2.5
- Fixed in:
- 13.2.6
- Disclosed:
- Sep 7, 2022
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.2.6
unknown
The WP Statistics plugin for WordPress is vulnerable to information disclosure via the Metabox REST API in versions up to, and including, 13.2.5. This allows all authenticated users to access statistics generated by the plugin.
- Affected:
- up to 13.2.6
- Fixed in:
- 13.2.6
- Disclosed:
- Sep 7, 2022
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.2.2
unknown
[en] Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product.
- Affected:
- up to 13.2.2
- Fixed in:
- 13.2.2
- Disclosed:
- Jun 13, 2022
CVE-2022-27231 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.2.2
unknown
[en] The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode characters
- Affected:
- up to 13.2.2
- Fixed in:
- 13.2.2
- Disclosed:
- Jun 6, 2022
CVE-2022-1005 on NVD →
WP Statistics <= 13.1.7 - Cross-Site Scripting
medium
Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product.
- CVSS:
- 6.1
- Affected:
- up to 13.2.0
- Fixed in:
- 13.2.0
- Disclosed:
- May 24, 2022
CVE-2022-27231 on NVD →
WP Statistic < 13.2.2 - Admin+ Stored Cross-Site Scripting
medium
- Affected:
- up to 13.2.2
- Fixed in:
- 13.2.2
- Disclosed:
- May 24, 2022
CVE-2022-27231 on NVD →
WP Statistics <= 13.2.1 - Reflected Cross-Site Scripting
medium
The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode characters
- CVSS:
- 6.1
- Affected:
- up to 13.2.2
- Fixed in:
- 13.2.2
- Disclosed:
- May 11, 2022
CVE-2022-1005 on NVD →
WP Statistics < 13.2.2 - Reflected Cross-Site Scripting
medium
- Affected:
- up to 13.2.2
- Fixed in:
- 13.2.2
- Disclosed:
- May 10, 2022
CVE-2022-1005 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6
unknown
[en] The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive informat...
- Affected:
- up to 13.1.6
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 24, 2022
CVE-2022-0651 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6
unknown
[en] The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive informatio...
- Affected:
- up to 13.1.6
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 24, 2022
CVE-2022-25148 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6
unknown
[en] The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in version...
- Affected:
- up to 13.1.6
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 24, 2022
CVE-2022-25149 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6
unknown
[en] The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a s...
- Affected:
- up to 13.1.6
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 24, 2022
CVE-2022-25305 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6
unknown
[en] The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrator...
- Affected:
- up to 13.1.6
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 24, 2022
CVE-2022-25306 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6
unknown
[en] The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators...
- Affected:
- up to 13.1.6
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 24, 2022
CVE-2022-25307 on NVD →
WP Statistics <= 13.1.5 - Unauthenticated Stored Cross-Site Scripting via platform
high
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view...
- CVSS:
- 7.2
- Affected:
- up to 13.1.5
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 17, 2022
CVE-2022-25307 on NVD →
WP Statistics < 13.1.6 - Multiple Unauthenticated Stored Cross-Site Scripting
high
- Affected:
- up to 13.1.6
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 17, 2022
CVE-2022-25305 on NVD →
WP Statistics <= 13.1.5 - Unauthenticated Blind SQL Injection via current_page_type
critical
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information,...
- CVSS:
- 9.8
- Affected:
- up to 13.1.5
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 16, 2022
CVE-2022-0651 on NVD →
WP Statistics <= 13.1.5 - Unauthenticated SQL Injection
critical
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in...
- CVSS:
- 9.8
- Affected:
- up to 13.1.5
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 16, 2022
CVE-2022-25148 on NVD →
WP Statistics <= 13.1.5 - Unauthenticated Blind SQL Injection via IP
critical
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up...
- CVSS:
- 9.8
- Affected:
- up to 13.1.5
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 16, 2022
CVE-2022-25149 on NVD →
WP Statistics <= 13.1.5 - Unauthenticated Stored Cross-Site Scripting via IP
high
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites...
- CVSS:
- 7.2
- Affected:
- up to 13.1.5
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 16, 2022
CVE-2022-25305 on NVD →
WP Statistics <= 13.1.5 - Unauthenticated Stored Cross-Site Scripting via browser
high
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators vie...
- CVSS:
- 7.2
- Affected:
- up to 13.1.5
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 16, 2022
CVE-2022-25306 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.5
unknown
[en] The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive info...
- Affected:
- up to 13.1.5
- Fixed in:
- 13.1.5
- Disclosed:
- Feb 16, 2022
CVE-2022-0513 on NVD →
WP Statistics < 13.1.6 - Unauthenticated Blind SQL Injection via IP
critical
- Affected:
- up to 13.1.6
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 16, 2022
CVE-2022-25149 on NVD →
WP Statistics < 13.1.6 - Unauthenticated Blind SQL Injection via current_page_id
critical
- Affected:
- up to 13.1.6
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 16, 2022
CVE-2022-25148 on NVD →
WP Statistics < 13.1.6 - Unauthenticated Blind SQL Injection via current_page_type
critical
- Affected:
- up to 13.1.6
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 16, 2022
CVE-2022-0651 on NVD →
WP Statistic < 13.1.6 - Reflected Cross-Site Scripting
medium
- Affected:
- up to 13.1.6
- Fixed in:
- 13.1.6
- Disclosed:
- Feb 16, 2022
WP Statistics <= 13.1.4 - Unauthenticated Blind SQL Injection
critical
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive informati...
- CVSS:
- 9.8
- Affected:
- up to 13.1.4
- Fixed in:
- 13.1.5
- Disclosed:
- Feb 10, 2022
CVE-2022-0513 on NVD →
WP Statistics < 13.1.5 - Unauthenticated Blind SQL Injection
critical
- Affected:
- up to 13.1.5
- Fixed in:
- 13.1.5
- Disclosed:
- Feb 10, 2022
CVE-2022-0513 on NVD →
WP Statistics <= 13.1.1 - Cross-Site Request Forgery to Arbitrary Plugin Activation and Deactivation
medium
The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing or incorrect nonce validation on the view() function. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins, via a forged reques...
- CVSS:
- 6.5
- Affected:
- up to 13.1.1
- Fixed in:
- 13.1.2
- Disclosed:
- Sep 11, 2021
CVE-2021-4333 on NVD →
WP Statistics < 13.1.2 - Arbitrary Plugin Activation/Deactivation via CSRF
medium
- Affected:
- up to 13.1.2
- Fixed in:
- 13.1.2
- Disclosed:
- Sep 11, 2021
CVE-2021-4333 on NVD →
WP Statistics <= 13.0.9 - Reflected Cross-Site Scripting
medium
The WP Statistic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 13.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...
- CVSS:
- 6.1
- Affected:
- up to 13.0.9
- Fixed in:
- 13.1
- Disclosed:
- Aug 30, 2021
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1
unknown
The WP Statistic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 13.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...
- Affected:
- up to 13.1
- Fixed in:
- 13.1
- Disclosed:
- Aug 30, 2021
WP Statistic < 13.1 - Reflected Cross-Site Scripting (XSS)
medium
- Affected:
- up to 13.1
- Fixed in:
- 13.1
- Disclosed:
- Aug 30, 2021
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.0.8
unknown
[en] The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated one...
- Affected:
- up to 13.0.8
- Fixed in:
- 13.0.8
- Disclosed:
- Jun 7, 2021
CVE-2021-24340 on NVD →
WP Statistics <= 13.0.7 - Unauthenticated SQL Injection
high
The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.
- CVSS:
- 7.5
- Affected:
- up to 13.0.8
- Fixed in:
- 13.0.8
- Disclosed:
- May 19, 2021
CVE-2021-24340 on NVD →
WP Statistics < 13.0.8 - Unauthenticated SQL Injection
critical
- Affected:
- up to 13.0.8
- Fixed in:
- 13.0.8
- Disclosed:
- May 19, 2021
CVE-2021-24340 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.0.8
unknown
Unauthenticated Time-Based Blind SQL Injection (SQLi) vulnerability discovered by WordFence in WordPress WP Statistics plugin (versions <= 13.0.7).
- Affected:
- up to 13.0.8
- Fixed in:
- 13.0.8
- Disclosed:
- May 18, 2021
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.8
unknown
[en] The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.
- Affected:
- up to 12.0.8
- Fixed in:
- 12.0.8
- Disclosed:
- Aug 14, 2019
CVE-2017-18515 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.7
unknown
[en] An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.
- Affected:
- up to 12.6.7
- Fixed in:
- 12.6.7
- Disclosed:
- Jul 4, 2019
CVE-2019-13275 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.7
unknown
Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability found by Antony Garand in WordPress WP Statistics plugin (version <= 12.6.6.1). The specific configuration needed for exploitation.
- Affected:
- up to 12.6.7
- Fixed in:
- 12.6.7
- Disclosed:
- Jul 4, 2019
WP Statistics < 12.6.7 - Unauthenticated Stored XSS Under Certain Configurations
medium
- Affected:
- up to 12.6.7
- Fixed in:
- 12.6.7
- Disclosed:
- Jul 3, 2019
WP Statistics <= 12.6.6.1 - Unauthenticated Blind SQL Injection
critical
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.
- CVSS:
- 9.8
- Affected:
- up to 12.6.6.1
- Fixed in:
- 12.6.7
- Disclosed:
- Jul 1, 2019
CVE-2019-13275 on NVD →
WP Statistics <= 12.6.6.1 - Unauthenticated Stored Cross-Site Scripting via IP Manipulation
high
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP spoofing in versions up to, and including, 12.6.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- CVSS:
- 7.2
- Affected:
- up to 12.6.6.1
- Fixed in:
- 12.6.7
- Disclosed:
- Jul 1, 2019
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.7
unknown
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP spoofing in versions up to, and including, 12.6.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- Affected:
- up to 12.6.7
- Fixed in:
- 12.6.7
- Disclosed:
- Jul 1, 2019
WP Statistics < 12.6.7 - Unauthenticated Blind SQL Injection
critical
- Affected:
- up to 12.6.7
- Fixed in:
- 12.6.7
- Disclosed:
- Jul 1, 2019
CVE-2019-13275 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.6.1
unknown
[en] The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.
- Affected:
- up to 12.6.6.1
- Fixed in:
- 12.6.6.1
- Disclosed:
- Jun 2, 2019
CVE-2019-12566 on NVD →
WP Statistics <= 12.6.5 - Stored Cross-Site Scripting
medium
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.
- CVSS:
- 6.4
- Affected:
- up to 12.6.5
- Fixed in:
- 12.6.6.1
- Disclosed:
- May 31, 2019
CVE-2019-12566 on NVD →
WP Statistics < 12.6.6.1 - Authenticated Stored XSS
medium
- Affected:
- up to 12.6.6.1
- Fixed in:
- 12.6.6.1
- Disclosed:
- May 30, 2019
CVE-2019-12566 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.4
unknown
[en] The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.
- Affected:
- up to 12.6.4
- Fixed in:
- 12.6.4
- Disclosed:
- Apr 23, 2019
CVE-2019-10864 on NVD →
WP Statistics <= 12.6.3 - Referer Cross-Site Scripting
medium
The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.
- CVSS:
- 6.1
- Affected:
- up to 12.6.3
- Fixed in:
- 12.6.4
- Disclosed:
- Apr 9, 2019
CVE-2019-10864 on NVD →
WP Statistics <= 12.6.3 - Referer Cross-Site Scripting (XSS)
medium
- Affected:
- up to 12.6.4
- Fixed in:
- 12.6.4
- Disclosed:
- Apr 9, 2019
CVE-2019-10864 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] >= 12.0.2 - <= 12.0.5
unknown
[en] WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing a cookie to code injection. This attack appear to be exploitable via an attacker must craft an...
- Affected:
- 12.0.2 – 12.0.5
- Fixed in:
- 12.0.5
- Disclosed:
- Jun 26, 2018
CVE-2018-1000556 on NVD →
WP Statistics <= 12.0.9 - Authenticated Cross-Site Scripting
medium
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.
- CVSS:
- 6.1
- Affected:
- up to 12.0.9
- Fixed in:
- 12.0.10
- Disclosed:
- Jul 7, 2017
CVE-2017-10991 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.10
unknown
[en] The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.
- Affected:
- up to 12.0.10
- Fixed in:
- 12.0.10
- Disclosed:
- Jul 7, 2017
CVE-2017-10991 on NVD →
WP Statistics <= 12.0.9 - Authenticated Cross-Site Scripting (XSS)
medium
- Affected:
- up to 12.0.10
- Fixed in:
- 12.0.10
- Disclosed:
- Jul 7, 2017
CVE-2017-10991 on NVD →
WP Statistics <= 12.0.8.1 - Reflected Cross-Site Scripting
medium
The WP Statistics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 12.0.9 due to insufficient input sanitization and output escaping on the IP parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...
- CVSS:
- 6.1
- Affected:
- up to 12.0.8.1
- Fixed in:
- 12.0.9
- Disclosed:
- Jul 3, 2017
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.9
unknown
The WP Statistics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 12.0.9 due to insufficient input sanitization and output escaping on the IP parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...
- Affected:
- up to 12.0.9
- Fixed in:
- 12.0.9
- Disclosed:
- Jul 3, 2017
WP Statistics < 12.0.9 - Authenticated Reflected Cross-Site Scripting (XSS)
medium
- Affected:
- up to 12.0.9
- Fixed in:
- 12.0.9
- Disclosed:
- Jul 3, 2017
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.8
unknown
WordPress WP Statistic plugin in version 12.0.7 and earlier versions vulnerable to Authenticated SQL Injection vulnerability due to lack of sanitization in user-provided data. In this case users even with subscriber rights could use this vulnerability to steal sensitive data.
The plugin already has a patched version. P...
- Affected:
- up to 12.0.8
- Fixed in:
- 12.0.8
- Disclosed:
- Jul 1, 2017
WP Statistics <= 12.0.7 - Authenticated SQL Injection
high
The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.
- CVSS:
- 8.8
- Affected:
- up to 12.0.7
- Fixed in:
- 12.0.8
- Disclosed:
- Jun 30, 2017
CVE-2017-18515 on NVD →
WP Statistics <= 12.0.7 - Authenticated SQL Injection
critical
- Affected:
- up to 12.0.8
- Fixed in:
- 12.0.8
- Disclosed:
- Jun 30, 2017
CVE-2017-18515 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.5
unknown
[en] Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 12.0.5
- Fixed in:
- 12.0.5
- Disclosed:
- Apr 28, 2017
CVE-2017-2135 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] <= 12.0.4
unknown
[en] Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 12.0.4
- Fixed in:
- 12.0.4
- Disclosed:
- Apr 28, 2017
CVE-2017-2147 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.5
unknown
[en] Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
- Affected:
- up to 12.0.5
- Fixed in:
- 12.0.5
- Disclosed:
- Apr 28, 2017
CVE-2017-2136 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.6
unknown
WordPress WP Statistics plugin v12.0.5 and earlier versions are vulnerable to Reflected Cross-Site Scripting (XSS) vulnerability. The value of the GET input “page-uri” is not sanitized, in the file /includes/log/page-statistics.php.
Update the plugin.
- Affected:
- up to 12.0.6
- Fixed in:
- 12.0.6
- Disclosed:
- Apr 28, 2017
WP Statistics <= 12.0.4 - Stored Cross-Site Scripting
medium
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
- CVSS:
- 6.1
- Affected:
- up to 12.0.4
- Fixed in:
- 12.0.5
- Disclosed:
- Apr 13, 2017
CVE-2017-2136 on NVD →
WP Statistics <= 12.0.4 - Reflected Cross-Site Scripting (XSS)
medium
- Affected:
- up to 12.0.5
- Fixed in:
- 12.0.5
- Disclosed:
- Apr 10, 2017
CVE-2017-2136 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.4.1
unknown
Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands.
Upgrade plugin.
- Affected:
- up to 9.4.1
- Fixed in:
- 9.4.1
- Disclosed:
- Nov 22, 2015
WP Statistics <= 9.5.1 - Cross-Site Scripting
medium
The WP Statistics plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 9.5.1 due to insufficient input sanitization and output escaping on the top-referrers page. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 9.5.1
- Fixed in:
- 9.5.2
- Disclosed:
- Aug 10, 2015
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.5.2
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 9.5.2
- Fixed in:
- 9.5.2
- Disclosed:
- Aug 10, 2015
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.5.2
unknown
The WP Statistics plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 9.5.1 due to insufficient input sanitization and output escaping on the top-referrers page. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 9.5.2
- Fixed in:
- 9.5.2
- Disclosed:
- Aug 10, 2015
WP Statistics <= 9.5.1 - Referer Cross-Site Scripting (XSS)
medium
- Affected:
- up to 9.5.2
- Fixed in:
- 9.5.2
- Disclosed:
- Aug 10, 2015
WP Statistics < 9.4.1 - Authenticated Blind SQL Injection
high
The WP Statistics plugin for WordPress is vulnerable to blind SQL Injection via the ‘page-id’ parameter in versions before 9.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers at the administrat...
- CVSS:
- 8.7
- Affected:
- up to 9.4.1
- Fixed in:
- 9.4.1
- Disclosed:
- Jul 9, 2015
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.4.1
unknown
The WP Statistics plugin for WordPress is vulnerable to blind SQL Injection via the ‘page-id’ parameter in versions before 9.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers at the administrat...
- Affected:
- up to 9.4.1
- Fixed in:
- 9.4.1
- Disclosed:
- Jul 9, 2015
WP Statistics <= 9.4 - Authenticated SQL Injection
critical
- Affected:
- up to 9.4.1
- Fixed in:
- 9.4.1
- Disclosed:
- Jul 9, 2015
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 2.2.5
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update the plugin.
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- Jun 25, 2015
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.1.3
unknown
This plugin is prone to a cross site scripting vulnerability because "above" parameter is vulnerable to cross site scripting. A malicious administration can hijack other users session, take control of another administrator's browser or install malware on their computer.
Update the plugin.
- Affected:
- up to 9.1.3
- Fixed in:
- 9.1.3
- Disclosed:
- May 15, 2015
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 8.3.1
unknown
This plugin is prone to stored and reflected cross site scripting vulnerabilities.
Update the plugin.
- Affected:
- up to 8.3.1
- Fixed in:
- 8.3.1
- Disclosed:
- May 15, 2015
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 8.5
unknown
This plugin is prone to unauthenticated referer header stored cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 8.5
- Fixed in:
- 8.5
- Disclosed:
- May 15, 2015
WP Statistics < 9.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Check for online users every:' & 'Coefficient per visitor:' fields in versions before 9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with admin-level privile...
- CVSS:
- 5.5
- Affected:
- up to 9.1.3
- Fixed in:
- 9.1.3
- Disclosed:
- Apr 15, 2015
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.1.3
unknown
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Check for online users every:' & 'Coefficient per visitor:' fields in versions before 9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with admin-level privile...
- Affected:
- up to 9.1.3
- Fixed in:
- 9.1.3
- Disclosed:
- Apr 15, 2015
WP Statistics <= 9.1.2 - Authenticated Stored Cross-Site Scripting (XSS)
medium
- Affected:
- up to 9.1.3
- Fixed in:
- 9.1.3
- Disclosed:
- Apr 15, 2015
WP Statistics <= 8.4 - Stored Cross-Site Scripting
high
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the referer link in versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- CVSS:
- 7.2
- Affected:
- up to 8.4
- Fixed in:
- 8.5
- Disclosed:
- Dec 3, 2014
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 8.5
unknown
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the referer link in versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- Affected:
- up to 8.5
- Fixed in:
- 8.5
- Disclosed:
- Dec 3, 2014
WP Statistics <= 8.4 - Unauthenticated Referer Header Stored XSS
medium
- Affected:
- up to 8.5
- Fixed in:
- 8.5
- Disclosed:
- Dec 3, 2014
WP Statistics <= 8.3 - Stored & Reflected Cross-Site Scripting (XSS)
medium
- Affected:
- up to 8.3.1
- Fixed in:
- 8.3.1
- Disclosed:
- Nov 20, 2014
WP Statistics < 8.3.1 - Multiple Cross-Site Scripting
high
The WP Statistics plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions before 8.3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 7.2
- Affected:
- up to 8.3.1
- Fixed in:
- 8.3.1
- Disclosed:
- Nov 20, 2014
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 8.3.1
unknown
The WP Statistics plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions before 8.3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 8.3.1
- Fixed in:
- 8.3.1
- Disclosed:
- Nov 20, 2014
WP Statistics <= 2.2.4 - Cross-Site Scripting
medium
The WP Statistics plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 2.2.4
- Fixed in:
- 2.2.5
- Disclosed:
- May 15, 2012
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 2.2.5
unknown
The WP Statistics plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- May 15, 2012
WP Statistics <= 2.2.4 - Cross-Site Scripting (XSS)
medium
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
- Disclosed:
- May 15, 2012
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1
unknown
The plugin does not sanitise and escape various user input before outputting it back in pages, which could lead to Cross-Site Scripting issues
- Affected:
- up to 13.1
- Fixed in:
- 13.1
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.7
unknown
Unauthenticated stored XSS via the forwarded IP if the plugin has a certain configuration
- Affected:
- up to 12.6.7
- Fixed in:
- 12.6.7
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.9
unknown
Version 12.0.8.1 and below of the WP Statistics WordPress Plugin was found to be vulnerable to Authenticated Reflected Cross-Site Scripting (XSS). The 'ip' GET parameter on the 'wps_visitors_page' page is output to a page without first being validated, sanitised or output encoded. This leads to Auth...
- Affected:
- up to 12.0.9
- Fixed in:
- 12.0.9
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.5.2
unknown
The WP Statistics WordPress plugin was affected by a Referer Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 9.5.2
- Fixed in:
- 9.5.2
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.4.1
unknown
The WP Statistics WordPress plugin was affected by an Authenticated SQL Injection security vulnerability.
- Affected:
- up to 9.4.1
- Fixed in:
- 9.4.1
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.1.3
unknown
The WP Statistics WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 9.1.3
- Fixed in:
- 9.1.3
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 8.5
unknown
On the "Statistics > Visitors" screen the referer link is not filtered. Malicious JavaScript can be injected by an unauthenticated user. This simple cURL command with a custom referer header makes it possible: curl -H 'Referer: javascript:alert(location.href);' 'http://wp.dev'
- Affected:
- up to 8.5
- Fixed in:
- 8.5
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 8.3.1
unknown
The WP Statistics WordPress plugin was affected by a Stored & Reflected Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 8.3.1
- Fixed in:
- 8.3.1
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 2.2.5
unknown
The WP Statistics WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 2.2.5
- Fixed in:
- 2.2.5
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6
unknown
The plugin does not escape various generated links before outputting them back in attributes, leading to Reflected Cross-Site Scripting
- Affected:
- up to 13.1.6
- Fixed in:
- 13.1.6
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.13.4
unknown
- Affected:
- up to 14.13.4
- Fixed in:
- 14.13.4
CVE-2025-3953 on NVD →
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.15.5
unknown
- Affected:
- up to 14.15.5
- Fixed in:
- 14.15.5
CVE-2025-9816 on NVD →