Cross-Site Scripting Vulnerability in WP Statistics Plugin by VeronaLabs
CVE-2026-97276
7.1HIGH
What is CVE-2026-97276?
The WP Statistics plugin by VeronaLabs is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper handling of user input during web page generation. This flaw allows attackers to inject malicious scripts that can be reflected off the web server, potentially compromising user data or session integrity. The vulnerability affects all versions from n/a up to 14.16.14, posing a significant risk to users who utilize this plugin for their WordPress sites.
Affected Version(s)
WP Statistics 0 <= 14.16.14