Stored Cross-Site Scripting Vulnerability in StatCounter Plugin for WordPress
CVE-2026-6275

6.4MEDIUM

What is CVE-2026-6275?

The StatCounter plugin for WordPress, up to version 2.1.1, is susceptible to Stored Cross-Site Scripting due to inadequate output escaping in the statcounter_addToTags() function. This vulnerability allows authenticated users with Author-level access to inject malicious scripts through the post author's nickname. When a post is accessed, the script executes in the context of the browser, potentially compromising user data and site integrity. Proper input validation and output encoding are essential to safeguard against such attacks.

Affected Version(s)

StatCounter – Free Real Time Visitor Stats 0 <= 2.1.1

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZAST.AI
.