Stored Cross-Site Scripting Vulnerability in StatCounter Plugin for WordPress
CVE-2026-6275
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 May 2026
What is CVE-2026-6275?
The StatCounter plugin for WordPress, up to version 2.1.1, is susceptible to Stored Cross-Site Scripting due to inadequate output escaping in the statcounter_addToTags() function. This vulnerability allows authenticated users with Author-level access to inject malicious scripts through the post author's nickname. When a post is accessed, the script executes in the context of the browser, potentially compromising user data and site integrity. Proper input validation and output encoding are essential to safeguard against such attacks.
Affected Version(s)
StatCounter β Free Real Time Visitor Stats 0 <= 2.1.1