Reflected Cross-Site Scripting Vulnerability in WP Statistics Plugin for WordPress
CVE-2026-97652
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-97652?
The WP Statistics plugin for WordPress is susceptible to reflected cross-site scripting (XSS) due to inadequate input sanitization and output escaping in its handling of the REQUEST_URI query parameter. This flaw allows unauthenticated attackers to inject arbitrary script code into web pages. If a user is tricked into clicking on a crafted link, the injected scripts can be executed, potentially leading to unauthorized actions on behalf of the user. It is crucial for users to update to version 14.16.15 or later to mitigate this risk.
Affected Version(s)
WP Statistics β Simple, privacy-friendly Google Analytics alternative 0 <= 14.16.14