Description
The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload can be planted without authentication via the public /wp-statistics/v2/hit REST endpoint, because the required signature is exposed on the public homepage and a base64-encoded page_uri POST parameter overrides the previously sanitized REQUEST_URI, allowing the malicious utm_campaign value to bypass sanitization and be stored in the database.
Published: 2026-08-19
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Statistics plugin, versions up to 14.16.8, is vulnerable to stored XSS through the 'utm_campaign' parameter. Attackers can place malicious JavaScript into that field via the public REST endpoint without authentication, because the endpoint accepts a base64‑encoded page_uri that overrides sanitization and the required signature is exposed on the homepage. The payload is then stored in the database and will be executed whenever a user visits a page containing the injected data, allowing arbitrary script execution in the victim’s browser.

Affected Systems

Any WordPress installation that has the WP Statistics plugin by veronalabs installed and running a version 14.16.8 or earlier is affected.

Risk and Exploitability

The vulnerability has a CVSS score of 7.2, indicating high severity. EPSS is reported as less than 1 %, showing a low current risk of exploitation, and it is not listed in the CISA KEV catalog. The exploit path is internet‑facing, requiring no credentials and relying solely on the public /wp-statistics/v2/hit endpoint, making it straightforward for attackers to inject malicious scripts that persist for all site visitors.

Generated by OpenCVE AI on August 20, 2026 at 19:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Statistics plugin to a version that includes the patch for the stored XSS vulnerability.
  • If an immediate update cannot be performed, block or restrict unauthenticated access to the /wp-statistics/v2/hit REST endpoint using web server rules, a firewall, or a web application firewall.
  • As a temporary workaround, add custom validation and output‑escaping logic for the 'utm_campaign' parameter or use a security plugin that enforces strict sanitization.

Generated by OpenCVE AI on August 20, 2026 at 19:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://github.com/wp-statistics/wp-statistics/commit/6ab74427778b89c9e88471e9dd7407d9055a9b34 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.7/assets/dev/javascript/helper.js#L267 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.7/includes/api/v2/class-wp-statistics-api-hit.php#L78 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.7/includes/class-wp-statistics-helper.php#L1462 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.7/includes/class-wp-statistics-hits.php#L102 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.7/views/components/tables/referred-visitors.php#L79 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.7/views/components/tables/visitors.php#L94 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.8/assets/dev/javascript/helper.js#L267 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.8/includes/api/v2/class-wp-statistics-api-hit.php#L78 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.8/includes/class-wp-statistics-helper.php#L1462 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.8/includes/class-wp-statistics-hits.php#L102 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.8/views/components/tables/referred-visitors.php#L79 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.8/views/components/tables/visitors.php#L94 cve-icon cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/b5baecfe-ce0b-4cec-8462-bfd7eadd41e9?source=cve cve-icon cve-icon
History

Wed, 19 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Veronalabs
Veronalabs wp Statistics – Simple, Privacy-friendly Google Analytics Alternative
Wordpress
Wordpress wordpress
Vendors & Products Veronalabs
Veronalabs wp Statistics – Simple, Privacy-friendly Google Analytics Alternative
Wordpress
Wordpress wordpress

Wed, 19 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Description The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload can be planted without authentication via the public /wp-statistics/v2/hit REST endpoint, because the required signature is exposed on the public homepage and a base64-encoded page_uri POST parameter overrides the previously sanitized REQUEST_URI, allowing the malicious utm_campaign value to bypass sanitization and be stored in the database.
Title WP Statistics <= 14.16.8 - Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Veronalabs Wp Statistics – Simple, Privacy-friendly Google Analytics Alternative
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-19T14:39:39.863Z

Reserved: 2026-07-14T18:46:23.515Z

Link: CVE-2026-15780

cve-icon Vulnrichment

Updated: 2026-08-19T13:52:00.496Z

cve-icon NVD

Status : Deferred

Published: 2026-08-19T07:16:27.773

Modified: 2026-08-20T12:48:10.287

Link: CVE-2026-15780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T19:15:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')