plugin

Wp Statistics Vulnerabilities

130 known security issues reported for the Wp Statistics WordPress plugin. Most recent disclosed Aug 18, 2026.

13 critical 20 high 35 medium

Running Wp Statistics on your site? Check whether your installed version is affected.

Scan your site free

WP Statistics <= 14.16.8 - Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter

high

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticate...

CVSS:
7.2
Affected:
up to 14.16.8
Fixed in:
14.16.9
Disclosed:
Aug 18, 2026

CVE-2026-15780 on NVD →

Statistics <= 14.16.9 - Authenticated (Subscriber+) Information Exposure

medium

The Statistics plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 14.16.9. This is due to missing capability check in the BaseMetabox AJAX handler before returning statistics data. This makes it possible for authenticated attackers, with subscriber-level access and ab...

CVSS:
4.3
Affected:
up to 14.16.9
Fixed in:
14.16.10
Disclosed:
Aug 3, 2026

CVE-2026-16562 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative <= 14.16.6 - Unauthenticated Stored Cross-Site Scripting

high

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 14.16.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web s...

CVSS:
7.2
Affected:
up to 14.16.6
Fixed in:
14.16.7
Disclosed:
Jun 1, 2026

CVE-2026-48839 on NVD →

WP Statistics <= 14.16.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure and Privacy Audit Manipulation

medium

The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing capability checks on multiple AJAX handlers including `wp_statistics_get_filters`, `wp_statistics_getPrivacyStatus`, `wp_statistics_updatePrivacyStatus`, and `wp_statistics...

CVSS:
6.5
Affected:
up to 14.16.4
Fixed in:
14.16.5
Disclosed:
Apr 16, 2026

CVE-2026-3488 on NVD →

WP Statistics <= 14.16.4 - Unauthenticated Stored Cross-Site Scripting via 'utm_source' Parameter

high

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and including, 14.16.4. This is due to insufficient input sanitization and output escaping. The plugin's referral parser copies the raw utm_source value into the source_name field wh...

CVSS:
7.2
Affected:
up to 14.16.4
Fixed in:
14.16.5
Disclosed:
Apr 16, 2026

CVE-2026-5231 on NVD →

WP Statistics <= 14.5.4 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header

high

The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent Header in all versions up to, and including, 14.5.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers...

CVSS:
7.2
Affected:
up to 14.15.4
Fixed in:
14.15.5
Disclosed:
Sep 26, 2025

CVE-2025-9816 on NVD →

WP Statistics < 14.15.5 - Unauthenticated Stored XSS via User-Agent Header

medium
Affected:
up to 14.15.5
Fixed in:
14.15.5
Disclosed:
Sep 26, 2025

CVE-2025-9816 on NVD →

WP Statistics <= 14.15 - Missing Authorization

medium

The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 14.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to per...

CVSS:
4.3
Affected:
up to 14.15
Fixed in:
14.15.2
Disclosed:
Aug 14, 2025

CVE-2025-55716 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.15.2

unknown

[en] Missing Authorization vulnerability in VeronaLabs WP Statistics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Statistics: from n/a through 14.15.

Affected:
up to 14.15.2
Fixed in:
14.15.2
Disclosed:
Aug 14, 2025

CVE-2025-55716 on NVD →

WP Statistics < 14.15.2 - Missing Authorization

medium
Affected:
up to 14.15.2
Fixed in:
14.15.2
Disclosed:
Aug 14, 2025

CVE-2025-55716 on NVD →

WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin <= 14.13.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Update

medium

The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'optionUpdater' function in all versions up to, and including, 14.13.3. This makes it possible for authenticated attackers, with Subscri...

CVSS:
5.4
Affected:
up to 14.13.3
Fixed in:
14.13.4
Disclosed:
Apr 29, 2025

CVE-2025-3953 on NVD →

WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin < 14.13.4 - Subscriber+ Arbitrary Plugin Settings Update

unknown
Affected:
up to 14.13.4
Fixed in:
14.13.4
Disclosed:
Apr 29, 2025

CVE-2025-3953 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.5.1

unknown

[en] The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...

Affected:
up to 14.5.1
Fixed in:
14.5.1
Disclosed:
Mar 13, 2024

CVE-2024-2194 on NVD →

WP Statistics <= 14.5 - Unauthenticated Stored Cross-Site Scripting

high

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will...

CVSS:
7.2
Affected:
up to 14.5
Fixed in:
14.5.1
Disclosed:
Mar 11, 2024

CVE-2024-2194 on NVD →

WP Statistics < 14.5.1 - Unauthenticated Stored Cross-Site Scripting

high
Affected:
up to 14.5.1
Fixed in:
14.5.1
Disclosed:
Mar 11, 2024

CVE-2024-2194 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.0

unknown

[en] The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to a...

Affected:
up to 14.0
Fixed in:
14.0
Disclosed:
Mar 27, 2023

CVE-2023-0955 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.2.11

unknown

[en] SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.

Affected:
up to 13.2.11
Fixed in:
13.2.11
Disclosed:
Mar 13, 2023

CVE-2022-38074 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.2

unknown

[en] The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing or incorrect nonce validation on the view() function. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins, via a forged r...

Affected:
up to 13.1.2
Fixed in:
13.1.2
Disclosed:
Mar 7, 2023

CVE-2021-4333 on NVD →

WP Statistics <= 13.2.16 - Authenticated (Admin+) SQL Injection

high

The WP Statistics plugin for WordPress is vulnerable to SQL Injection via the $days_time_list value in versions up to, and including, 13.2.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with...

CVSS:
7.2
Affected:
up to 13.2.16
Fixed in:
14.0
Disclosed:
Mar 6, 2023

CVE-2023-0955 on NVD →

WP Statistics < 14.0 - Authenticated SQLi

unknown
Affected:
up to 14.0
Fixed in:
14.0
Disclosed:
Mar 6, 2023

CVE-2023-0955 on NVD →

WP Statistics <= 13.2.10 - Authenticated (Subscriber+) SQL Injection

high

The WP Statistics plugin for WordPress is vulnerable to SQL Injection via the ‘limit’ parameter in versions up to, and including, 13.2.10 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for subscriber-level attackers to ap...

CVSS:
8.8
Affected:
up to 13.2.10
Fixed in:
13.2.11
Disclosed:
Jan 31, 2023

CVE-2022-38074 on NVD →

WP Statistics < 13.2.11 - Subscriber+ SQLi

unknown
Affected:
up to 13.2.11
Fixed in:
13.2.11
Disclosed:
Jan 31, 2023

CVE-2022-38074 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.2.9

unknown

[en] The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to...

Affected:
up to 13.2.9
Fixed in:
13.2.9
Disclosed:
Jan 23, 2023

CVE-2022-4230 on NVD →

WP Statistics <= 13.2.8 - Authenticated (Admin+) SQL Injection

high

The WP Statistics plugin for WordPress is vulnerable to SQL Injection via the $search_engine value in versions up to, and including, 13.2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with a...

CVSS:
7.2
Affected:
up to 13.2.8
Fixed in:
13.2.9
Disclosed:
Dec 27, 2022

CVE-2022-4230 on NVD →

WP Statistics < 13.2.9 - Authenticated SQLi

unknown
Affected:
up to 13.2.9
Fixed in:
13.2.9
Disclosed:
Dec 27, 2022

CVE-2022-4230 on NVD →

WP Statistics <= 13.2.5 - Authenticated (Subscriber+) SQL Injection

high

The WP Statistics plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘agent’ parameter in versions up to, and including, 13.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated att...

CVSS:
8.8
Affected:
up to 13.2.5
Fixed in:
13.2.6
Disclosed:
Sep 8, 2022

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.2.6

unknown

The WP Statistics plugin for WordPress is vulnerable to time-based blind SQL Injection via the ‘agent’ parameter in versions up to, and including, 13.2.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated att...

Affected:
up to 13.2.6
Fixed in:
13.2.6
Disclosed:
Sep 8, 2022

WP Statistics <= 13.2.5 - Information Disclosure

medium

The WP Statistics plugin for WordPress is vulnerable to information disclosure via the Metabox REST API in versions up to, and including, 13.2.5. This allows all authenticated users to access statistics generated by the plugin.

CVSS:
4.3
Affected:
13.2.5 – 13.2.5
Fixed in:
13.2.6
Disclosed:
Sep 7, 2022

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.2.6

unknown

The WP Statistics plugin for WordPress is vulnerable to information disclosure via the Metabox REST API in versions up to, and including, 13.2.5. This allows all authenticated users to access statistics generated by the plugin.

Affected:
up to 13.2.6
Fixed in:
13.2.6
Disclosed:
Sep 7, 2022

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.2.2

unknown

[en] Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product.

Affected:
up to 13.2.2
Fixed in:
13.2.2
Disclosed:
Jun 13, 2022

CVE-2022-27231 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.2.2

unknown

[en] The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode characters

Affected:
up to 13.2.2
Fixed in:
13.2.2
Disclosed:
Jun 6, 2022

CVE-2022-1005 on NVD →

WP Statistics <= 13.1.7 - Cross-Site Scripting

medium

Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product.

CVSS:
6.1
Affected:
up to 13.2.0
Fixed in:
13.2.0
Disclosed:
May 24, 2022

CVE-2022-27231 on NVD →

WP Statistic < 13.2.2 - Admin+ Stored Cross-Site Scripting

medium
Affected:
up to 13.2.2
Fixed in:
13.2.2
Disclosed:
May 24, 2022

CVE-2022-27231 on NVD →

WP Statistics <= 13.2.1 - Reflected Cross-Site Scripting

medium

The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode characters

CVSS:
6.1
Affected:
up to 13.2.2
Fixed in:
13.2.2
Disclosed:
May 11, 2022

CVE-2022-1005 on NVD →

WP Statistics < 13.2.2 - Reflected Cross-Site Scripting

medium
Affected:
up to 13.2.2
Fixed in:
13.2.2
Disclosed:
May 10, 2022

CVE-2022-1005 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6

unknown

[en] The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive informat...

Affected:
up to 13.1.6
Fixed in:
13.1.6
Disclosed:
Feb 24, 2022

CVE-2022-0651 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6

unknown

[en] The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive informatio...

Affected:
up to 13.1.6
Fixed in:
13.1.6
Disclosed:
Feb 24, 2022

CVE-2022-25148 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6

unknown

[en] The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in version...

Affected:
up to 13.1.6
Fixed in:
13.1.6
Disclosed:
Feb 24, 2022

CVE-2022-25149 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6

unknown

[en] The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a s...

Affected:
up to 13.1.6
Fixed in:
13.1.6
Disclosed:
Feb 24, 2022

CVE-2022-25305 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6

unknown

[en] The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrator...

Affected:
up to 13.1.6
Fixed in:
13.1.6
Disclosed:
Feb 24, 2022

CVE-2022-25306 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6

unknown

[en] The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators...

Affected:
up to 13.1.6
Fixed in:
13.1.6
Disclosed:
Feb 24, 2022

CVE-2022-25307 on NVD →

WP Statistics <= 13.1.5 - Unauthenticated Stored Cross-Site Scripting via platform

high

The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view...

CVSS:
7.2
Affected:
up to 13.1.5
Fixed in:
13.1.6
Disclosed:
Feb 17, 2022

CVE-2022-25307 on NVD →

WP Statistics < 13.1.6 - Multiple Unauthenticated Stored Cross-Site Scripting

high
Affected:
up to 13.1.6
Fixed in:
13.1.6
Disclosed:
Feb 17, 2022

CVE-2022-25305 on NVD →

WP Statistics <= 13.1.5 - Unauthenticated Blind SQL Injection via current_page_type

critical

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information,...

CVSS:
9.8
Affected:
up to 13.1.5
Fixed in:
13.1.6
Disclosed:
Feb 16, 2022

CVE-2022-0651 on NVD →

WP Statistics <= 13.1.5 - Unauthenticated SQL Injection

critical

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in...

CVSS:
9.8
Affected:
up to 13.1.5
Fixed in:
13.1.6
Disclosed:
Feb 16, 2022

CVE-2022-25148 on NVD →

WP Statistics <= 13.1.5 - Unauthenticated Blind SQL Injection via IP

critical

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up...

CVSS:
9.8
Affected:
up to 13.1.5
Fixed in:
13.1.6
Disclosed:
Feb 16, 2022

CVE-2022-25149 on NVD →

WP Statistics <= 13.1.5 - Unauthenticated Stored Cross-Site Scripting via IP

high

The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites...

CVSS:
7.2
Affected:
up to 13.1.5
Fixed in:
13.1.6
Disclosed:
Feb 16, 2022

CVE-2022-25305 on NVD →

WP Statistics <= 13.1.5 - Unauthenticated Stored Cross-Site Scripting via browser

high

The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators vie...

CVSS:
7.2
Affected:
up to 13.1.5
Fixed in:
13.1.6
Disclosed:
Feb 16, 2022

CVE-2022-25306 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.5

unknown

[en] The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive info...

Affected:
up to 13.1.5
Fixed in:
13.1.5
Disclosed:
Feb 16, 2022

CVE-2022-0513 on NVD →

WP Statistics < 13.1.6 - Unauthenticated Blind SQL Injection via IP

critical
Affected:
up to 13.1.6
Fixed in:
13.1.6
Disclosed:
Feb 16, 2022

CVE-2022-25149 on NVD →

WP Statistics < 13.1.6 - Unauthenticated Blind SQL Injection via current_page_id

critical
Affected:
up to 13.1.6
Fixed in:
13.1.6
Disclosed:
Feb 16, 2022

CVE-2022-25148 on NVD →

WP Statistics < 13.1.6 - Unauthenticated Blind SQL Injection via current_page_type

critical
Affected:
up to 13.1.6
Fixed in:
13.1.6
Disclosed:
Feb 16, 2022

CVE-2022-0651 on NVD →

WP Statistic < 13.1.6 - Reflected Cross-Site Scripting

medium
Affected:
up to 13.1.6
Fixed in:
13.1.6
Disclosed:
Feb 16, 2022

WP Statistics <= 13.1.4 - Unauthenticated Blind SQL Injection

critical

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive informati...

CVSS:
9.8
Affected:
up to 13.1.4
Fixed in:
13.1.5
Disclosed:
Feb 10, 2022

CVE-2022-0513 on NVD →

WP Statistics < 13.1.5 - Unauthenticated Blind SQL Injection

critical
Affected:
up to 13.1.5
Fixed in:
13.1.5
Disclosed:
Feb 10, 2022

CVE-2022-0513 on NVD →

WP Statistics <= 13.1.1 - Cross-Site Request Forgery to Arbitrary Plugin Activation and Deactivation

medium

The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing or incorrect nonce validation on the view() function. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins, via a forged reques...

CVSS:
6.5
Affected:
up to 13.1.1
Fixed in:
13.1.2
Disclosed:
Sep 11, 2021

CVE-2021-4333 on NVD →

WP Statistics < 13.1.2 - Arbitrary Plugin Activation/Deactivation via CSRF

medium
Affected:
up to 13.1.2
Fixed in:
13.1.2
Disclosed:
Sep 11, 2021

CVE-2021-4333 on NVD →

WP Statistics <= 13.0.9 - Reflected Cross-Site Scripting

medium

The WP Statistic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 13.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...

CVSS:
6.1
Affected:
up to 13.0.9
Fixed in:
13.1
Disclosed:
Aug 30, 2021

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1

unknown

The WP Statistic plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 13.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully t...

Affected:
up to 13.1
Fixed in:
13.1
Disclosed:
Aug 30, 2021

WP Statistic < 13.1 - Reflected Cross-Site Scripting (XSS)

medium
Affected:
up to 13.1
Fixed in:
13.1
Disclosed:
Aug 30, 2021

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.0.8

unknown

[en] The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated one...

Affected:
up to 13.0.8
Fixed in:
13.0.8
Disclosed:
Jun 7, 2021

CVE-2021-24340 on NVD →

WP Statistics <= 13.0.7 - Unauthenticated SQL Injection

high

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

CVSS:
7.5
Affected:
up to 13.0.8
Fixed in:
13.0.8
Disclosed:
May 19, 2021

CVE-2021-24340 on NVD →

WP Statistics < 13.0.8 - Unauthenticated SQL Injection

critical
Affected:
up to 13.0.8
Fixed in:
13.0.8
Disclosed:
May 19, 2021

CVE-2021-24340 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.0.8

unknown

Unauthenticated Time-Based Blind SQL Injection (SQLi) vulnerability discovered by WordFence in WordPress WP Statistics plugin (versions <= 13.0.7).

Affected:
up to 13.0.8
Fixed in:
13.0.8
Disclosed:
May 18, 2021

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.8

unknown

[en] The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.

Affected:
up to 12.0.8
Fixed in:
12.0.8
Disclosed:
Aug 14, 2019

CVE-2017-18515 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.7

unknown

[en] An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.

Affected:
up to 12.6.7
Fixed in:
12.6.7
Disclosed:
Jul 4, 2019

CVE-2019-13275 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.7

unknown

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability found by Antony Garand in WordPress WP Statistics plugin (version <= 12.6.6.1). The specific configuration needed for exploitation.

Affected:
up to 12.6.7
Fixed in:
12.6.7
Disclosed:
Jul 4, 2019

WP Statistics < 12.6.7 - Unauthenticated Stored XSS Under Certain Configurations

medium
Affected:
up to 12.6.7
Fixed in:
12.6.7
Disclosed:
Jul 3, 2019

WP Statistics <= 12.6.6.1 - Unauthenticated Blind SQL Injection

critical

An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.

CVSS:
9.8
Affected:
up to 12.6.6.1
Fixed in:
12.6.7
Disclosed:
Jul 1, 2019

CVE-2019-13275 on NVD →

WP Statistics <= 12.6.6.1 - Unauthenticated Stored Cross-Site Scripting via IP Manipulation

high

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP spoofing in versions up to, and including, 12.6.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...

CVSS:
7.2
Affected:
up to 12.6.6.1
Fixed in:
12.6.7
Disclosed:
Jul 1, 2019

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.7

unknown

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP spoofing in versions up to, and including, 12.6.6.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...

Affected:
up to 12.6.7
Fixed in:
12.6.7
Disclosed:
Jul 1, 2019

WP Statistics < 12.6.7 - Unauthenticated Blind SQL Injection

critical
Affected:
up to 12.6.7
Fixed in:
12.6.7
Disclosed:
Jul 1, 2019

CVE-2019-13275 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.6.1

unknown

[en] The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.

Affected:
up to 12.6.6.1
Fixed in:
12.6.6.1
Disclosed:
Jun 2, 2019

CVE-2019-12566 on NVD →

WP Statistics <= 12.6.5 - Stored Cross-Site Scripting

medium

The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.

CVSS:
6.4
Affected:
up to 12.6.5
Fixed in:
12.6.6.1
Disclosed:
May 31, 2019

CVE-2019-12566 on NVD →

WP Statistics < 12.6.6.1 - Authenticated Stored XSS

medium
Affected:
up to 12.6.6.1
Fixed in:
12.6.6.1
Disclosed:
May 30, 2019

CVE-2019-12566 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.4

unknown

[en] The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.

Affected:
up to 12.6.4
Fixed in:
12.6.4
Disclosed:
Apr 23, 2019

CVE-2019-10864 on NVD →

WP Statistics <= 12.6.3 - Referer Cross-Site Scripting

medium

The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.

CVSS:
6.1
Affected:
up to 12.6.3
Fixed in:
12.6.4
Disclosed:
Apr 9, 2019

CVE-2019-10864 on NVD →

WP Statistics <= 12.6.3 - Referer Cross-Site Scripting (XSS)

medium
Affected:
up to 12.6.4
Fixed in:
12.6.4
Disclosed:
Apr 9, 2019

CVE-2019-10864 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] >= 12.0.2 - <= 12.0.5

unknown

[en] WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing a cookie to code injection. This attack appear to be exploitable via an attacker must craft an...

Affected:
12.0.2 – 12.0.5
Fixed in:
12.0.5
Disclosed:
Jun 26, 2018

CVE-2018-1000556 on NVD →

WP Statistics <= 12.0.9 - Authenticated Cross-Site Scripting

medium

The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.

CVSS:
6.1
Affected:
up to 12.0.9
Fixed in:
12.0.10
Disclosed:
Jul 7, 2017

CVE-2017-10991 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.10

unknown

[en] The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.

Affected:
up to 12.0.10
Fixed in:
12.0.10
Disclosed:
Jul 7, 2017

CVE-2017-10991 on NVD →

WP Statistics <= 12.0.9 - Authenticated Cross-Site Scripting (XSS)

medium
Affected:
up to 12.0.10
Fixed in:
12.0.10
Disclosed:
Jul 7, 2017

CVE-2017-10991 on NVD →

WP Statistics <= 12.0.8.1 - Reflected Cross-Site Scripting

medium

The WP Statistics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 12.0.9 due to insufficient input sanitization and output escaping on the IP parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...

CVSS:
6.1
Affected:
up to 12.0.8.1
Fixed in:
12.0.9
Disclosed:
Jul 3, 2017

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.9

unknown

The WP Statistics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions before 12.0.9 due to insufficient input sanitization and output escaping on the IP parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successf...

Affected:
up to 12.0.9
Fixed in:
12.0.9
Disclosed:
Jul 3, 2017

WP Statistics < 12.0.9 - Authenticated Reflected Cross-Site Scripting (XSS)

medium
Affected:
up to 12.0.9
Fixed in:
12.0.9
Disclosed:
Jul 3, 2017

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.8

unknown

WordPress WP Statistic plugin in version 12.0.7 and earlier versions vulnerable to Authenticated SQL Injection vulnerability due to lack of sanitization in user-provided data. In this case users even with subscriber rights could use this vulnerability to steal sensitive data. The plugin already has a patched version. P...

Affected:
up to 12.0.8
Fixed in:
12.0.8
Disclosed:
Jul 1, 2017

WP Statistics <= 12.0.7 - Authenticated SQL Injection

high

The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.

CVSS:
8.8
Affected:
up to 12.0.7
Fixed in:
12.0.8
Disclosed:
Jun 30, 2017

CVE-2017-18515 on NVD →

WP Statistics <= 12.0.7 - Authenticated SQL Injection

critical
Affected:
up to 12.0.8
Fixed in:
12.0.8
Disclosed:
Jun 30, 2017

CVE-2017-18515 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.5

unknown

[en] Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 12.0.5
Fixed in:
12.0.5
Disclosed:
Apr 28, 2017

CVE-2017-2135 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] <= 12.0.4

unknown

[en] Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 12.0.4
Fixed in:
12.0.4
Disclosed:
Apr 28, 2017

CVE-2017-2147 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.5

unknown

[en] Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.

Affected:
up to 12.0.5
Fixed in:
12.0.5
Disclosed:
Apr 28, 2017

CVE-2017-2136 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.6

unknown

WordPress WP Statistics plugin v12.0.5 and earlier versions are vulnerable to Reflected Cross-Site Scripting (XSS) vulnerability. The value of the GET input “page-uri” is not sanitized, in the file /includes/log/page-statistics.php. Update the plugin.

Affected:
up to 12.0.6
Fixed in:
12.0.6
Disclosed:
Apr 28, 2017

WP Statistics <= 12.0.4 - Stored Cross-Site Scripting

medium

Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.

CVSS:
6.1
Affected:
up to 12.0.4
Fixed in:
12.0.5
Disclosed:
Apr 13, 2017

CVE-2017-2136 on NVD →

WP Statistics <= 12.0.4 - Reflected Cross-Site Scripting (XSS)

medium
Affected:
up to 12.0.5
Fixed in:
12.0.5
Disclosed:
Apr 10, 2017

CVE-2017-2136 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.4.1

unknown

Because of this vulnerability, remote authenticated users can execute arbitrary SQL commands. Upgrade plugin.

Affected:
up to 9.4.1
Fixed in:
9.4.1
Disclosed:
Nov 22, 2015

WP Statistics <= 9.5.1 - Cross-Site Scripting

medium

The WP Statistics plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 9.5.1 due to insufficient input sanitization and output escaping on the top-referrers page. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 9.5.1
Fixed in:
9.5.2
Disclosed:
Aug 10, 2015

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.5.2

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 9.5.2
Fixed in:
9.5.2
Disclosed:
Aug 10, 2015

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.5.2

unknown

The WP Statistics plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 9.5.1 due to insufficient input sanitization and output escaping on the top-referrers page. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 9.5.2
Fixed in:
9.5.2
Disclosed:
Aug 10, 2015

WP Statistics <= 9.5.1 - Referer Cross-Site Scripting (XSS)

medium
Affected:
up to 9.5.2
Fixed in:
9.5.2
Disclosed:
Aug 10, 2015

WP Statistics < 9.4.1 - Authenticated Blind SQL Injection

high

The WP Statistics plugin for WordPress is vulnerable to blind SQL Injection via the ‘page-id’ parameter in versions before 9.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers at the administrat...

CVSS:
8.7
Affected:
up to 9.4.1
Fixed in:
9.4.1
Disclosed:
Jul 9, 2015

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.4.1

unknown

The WP Statistics plugin for WordPress is vulnerable to blind SQL Injection via the ‘page-id’ parameter in versions before 9.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers at the administrat...

Affected:
up to 9.4.1
Fixed in:
9.4.1
Disclosed:
Jul 9, 2015

WP Statistics <= 9.4 - Authenticated SQL Injection

critical
Affected:
up to 9.4.1
Fixed in:
9.4.1
Disclosed:
Jul 9, 2015

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 2.2.5

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
Jun 25, 2015

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.1.3

unknown

This plugin is prone to a cross site scripting vulnerability because "above" parameter is vulnerable to cross site scripting. A malicious administration can hijack other users session, take control of another administrator's browser or install malware on their computer. Update the plugin.

Affected:
up to 9.1.3
Fixed in:
9.1.3
Disclosed:
May 15, 2015

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 8.3.1

unknown

This plugin is prone to stored and reflected cross site scripting vulnerabilities. Update the plugin.

Affected:
up to 8.3.1
Fixed in:
8.3.1
Disclosed:
May 15, 2015

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 8.5

unknown

This plugin is prone to unauthenticated referer header stored cross site scripting vulnerability. Update the plugin.

Affected:
up to 8.5
Fixed in:
8.5
Disclosed:
May 15, 2015

WP Statistics < 9.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Check for online users every:' & 'Coefficient per visitor:' fields in versions before 9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with admin-level privile...

CVSS:
5.5
Affected:
up to 9.1.3
Fixed in:
9.1.3
Disclosed:
Apr 15, 2015

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.1.3

unknown

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Check for online users every:' & 'Coefficient per visitor:' fields in versions before 9.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with admin-level privile...

Affected:
up to 9.1.3
Fixed in:
9.1.3
Disclosed:
Apr 15, 2015

WP Statistics <= 9.1.2 - Authenticated Stored Cross-Site Scripting (XSS)

medium
Affected:
up to 9.1.3
Fixed in:
9.1.3
Disclosed:
Apr 15, 2015

WP Statistics <= 8.4 - Stored Cross-Site Scripting

high

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the referer link in versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...

CVSS:
7.2
Affected:
up to 8.4
Fixed in:
8.5
Disclosed:
Dec 3, 2014

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 8.5

unknown

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the referer link in versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...

Affected:
up to 8.5
Fixed in:
8.5
Disclosed:
Dec 3, 2014

WP Statistics <= 8.4 - Unauthenticated Referer Header Stored XSS

medium
Affected:
up to 8.5
Fixed in:
8.5
Disclosed:
Dec 3, 2014

WP Statistics <= 8.3 - Stored & Reflected Cross-Site Scripting (XSS)

medium
Affected:
up to 8.3.1
Fixed in:
8.3.1
Disclosed:
Nov 20, 2014

WP Statistics < 8.3.1 - Multiple Cross-Site Scripting

high

The WP Statistics plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions before 8.3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.2
Affected:
up to 8.3.1
Fixed in:
8.3.1
Disclosed:
Nov 20, 2014

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 8.3.1

unknown

The WP Statistics plugin for WordPress is vulnerable to Multiple Cross-Site Scripting via several parameters in versions before 8.3.1 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 8.3.1
Fixed in:
8.3.1
Disclosed:
Nov 20, 2014

WP Statistics <= 2.2.4 - Cross-Site Scripting

medium

The WP Statistics plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 2.2.4
Fixed in:
2.2.5
Disclosed:
May 15, 2012

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 2.2.5

unknown

The WP Statistics plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
May 15, 2012

WP Statistics <= 2.2.4 - Cross-Site Scripting (XSS)

medium
Affected:
up to 2.2.5
Fixed in:
2.2.5
Disclosed:
May 15, 2012

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1

unknown

The plugin does not sanitise and escape various user input before outputting it back in pages, which could lead to Cross-Site Scripting issues

Affected:
up to 13.1
Fixed in:
13.1

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.6.7

unknown

Unauthenticated stored XSS via the forwarded IP if the plugin has a certain configuration

Affected:
up to 12.6.7
Fixed in:
12.6.7

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 12.0.9

unknown

Version 12.0.8.1 and below of the WP Statistics WordPress Plugin was found to be vulnerable to Authenticated Reflected Cross-Site Scripting (XSS). The &#039;ip&#039; GET parameter on the &#039;wps_visitors_page&#039; page is output to a page without first being validated, sanitised or output encoded. This leads to Auth...

Affected:
up to 12.0.9
Fixed in:
12.0.9

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.5.2

unknown

The WP Statistics WordPress plugin was affected by a Referer Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 9.5.2
Fixed in:
9.5.2

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.4.1

unknown

The WP Statistics WordPress plugin was affected by an Authenticated SQL Injection security vulnerability.

Affected:
up to 9.4.1
Fixed in:
9.4.1

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 9.1.3

unknown

The WP Statistics WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 9.1.3
Fixed in:
9.1.3

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 8.5

unknown

On the &quot;Statistics &gt; Visitors&quot; screen the referer link is not filtered. Malicious JavaScript can be injected by an unauthenticated user. This simple cURL command with a custom referer header makes it possible: curl -H &#039;Referer: javascript:alert(location.href);&#039; &#039;http://wp.dev&#039;

Affected:
up to 8.5
Fixed in:
8.5

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 8.3.1

unknown

The WP Statistics WordPress plugin was affected by a Stored &amp; Reflected Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 8.3.1
Fixed in:
8.3.1

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 2.2.5

unknown

The WP Statistics WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 2.2.5
Fixed in:
2.2.5

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6

unknown

The plugin does not escape various generated links before outputting them back in attributes, leading to Reflected Cross-Site Scripting

Affected:
up to 13.1.6
Fixed in:
13.1.6

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.13.4

unknown
Affected:
up to 14.13.4
Fixed in:
14.13.4

CVE-2025-3953 on NVD →

WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.15.5

unknown
Affected:
up to 14.15.5
Fixed in:
14.15.5

CVE-2025-9816 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database