Stored Cross-Site Scripting in Independent Analytics Plugin for WordPress
CVE-2026-17506

7.2HIGH

What is CVE-2026-17506?

The Independent Analytics plugin for WordPress contains a vulnerability that enables Stored Cross-Site Scripting through the 404 not_found_url tracking parameter. This susceptibility occurs in versions up to and including 2.15.0 due to improper URL handling in the get_cell_content() function. The function executes urldecode() after esc_url(), allowing percent-encoded HTML to bypass URL validation. Consequently, this raw markup can be injected into pages when accessed by users. Since the public REST endpoint /iawp/search permits unauthenticated requests as long as they include a valid signature, attackers can exploit this flaw to insert malicious scripts that execute whenever a user visits the compromised page.

Affected Version(s)

Independent Analytics – WordPress Analytics Plugin 0 <= 2.15.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

daroo
.