Reflected Cross-Site Scripting Vulnerability in WP Statistics Plugin for WordPress
CVE-2026-97652

6.1MEDIUM

What is CVE-2026-97652?

The WP Statistics plugin for WordPress is susceptible to reflected cross-site scripting (XSS) due to inadequate input sanitization and output escaping in its handling of the REQUEST_URI query parameter. This flaw allows unauthenticated attackers to inject arbitrary script code into web pages. If a user is tricked into clicking on a crafted link, the injected scripts can be executed, potentially leading to unauthorized actions on behalf of the user. It is crucial for users to update to version 14.16.15 or later to mitigate this risk.

Affected Version(s)

WP Statistics – Simple, privacy-friendly Google Analytics alternative 0 <= 14.16.14

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman
.