Stored Cross-Site Scripting in StatCounter Plugin for WordPress
CVE-2025-13048
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 February 2026
What is CVE-2025-13048?
The StatCounter β Free Real Time Visitor Stats plugin for WordPress has a vulnerability that exposes it to Stored Cross-Site Scripting (XSS) attacks. This issue arises from inadequate input sanitization and output escaping related to the user's Nickname field. Authenticated users with Contributor-level access or higher can exploit this vulnerability to inject malicious web scripts. These scripts will execute whenever a user accesses affected pages, posing serious risks to the site's integrity and user safety.
Affected Version(s)
StatCounter β Free Real Time Visitor Stats 0 <= 2.1.0