Stored Cross-Site Scripting in Independent Analytics Plugin for WordPress
CVE-2026-17506
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-17506?
The Independent Analytics plugin for WordPress contains a vulnerability that enables Stored Cross-Site Scripting through the 404 not_found_url tracking parameter. This susceptibility occurs in versions up to and including 2.15.0 due to improper URL handling in the get_cell_content() function. The function executes urldecode() after esc_url(), allowing percent-encoded HTML to bypass URL validation. Consequently, this raw markup can be injected into pages when accessed by users. Since the public REST endpoint /iawp/search permits unauthenticated requests as long as they include a valid signature, attackers can exploit this flaw to insert malicious scripts that execute whenever a user visits the compromised page.
Affected Version(s)
Independent Analytics β WordPress Analytics Plugin 0 <= 2.15.0