Description
The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2026-08-14
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP‑Stats plugin for WordPress is affected by a stored cross‑site scripting vulnerability in every release up to and including 2.56. The flaw stems from insufficient input sanitization and inadequate output escaping, enabling an unauthenticated attacker to inject any JavaScript payload that will be stored and executed when a user visits the compromised page.

Affected Systems

The vulnerable plugin is distributed by gamerz as WP‑Stats. All versions of WP‑Stats 2.56 or older are impacted; any site installing those releases with WordPress is potentially affected.

Risk and Exploitability

The CVSS score of 7.2 reflects high severity, and the flaw can be exploited without any authentication. Although no EPSS score is available and it is not listed in CISA KEV, the stored nature of the XSS means that once an attacker crafts and submits an injection via any plugin input, the malicious script will run in the browsers of every visitor to that page. The impact is confined to client‑side code execution, which can lead to cookie theft, session hijacking, defacement, or further malware delivery.

Generated by OpenCVE AI on August 14, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP‑Stats plugin to a version newer than 2.56 or to the latest available release.
  • Temporarily deactivate or remove the WP‑Stats plugin until a patched version is available to eliminate the risk of exploitation.
  • Perform a thorough review of the database and relevant code to identify and clean any stored malicious scripts that may have been inserted while the vulnerability was active.

Generated by OpenCVE AI on August 14, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Gamerz
Gamerz wp-stats
Wordpress
Wordpress wordpress
Vendors & Products Gamerz
Gamerz wp-stats
Wordpress
Wordpress wordpress

Fri, 14 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Description The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title WP-Stats <= 2.56 - Unauthenticated Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Gamerz Wp-stats
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-14T10:25:41.585Z

Reserved: 2026-08-13T19:37:39.500Z

Link: CVE-2026-19794

cve-icon Vulnrichment

Updated: 2026-08-14T10:25:31.218Z

cve-icon NVD

Status : Deferred

Published: 2026-08-14T08:17:38.130

Modified: 2026-08-14T19:09:56.813

Link: CVE-2026-19794

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T09:45:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')