Unauthenticated Cross Site Scripting Vulnerability in WP Statistics Plugin
CVE-2026-84774

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 September 2026

What is CVE-2026-84774?

The WP Statistics plugin, versions 14.16.11 and below, has a vulnerability that allows unauthenticated users to execute arbitrary JavaScript code in the context of the affected website. This can result in various forms of abuse, including data theft or phishing attacks, compromising the site's security and potentially affecting its users.

Affected Version(s)

WP Statistics <= 14.16.11

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TwinSecKR | Patchstack Bug Bounty Program
.