Impact
The WP‑Stats plugin for WordPress is affected by a stored cross‑site scripting vulnerability in every release up to and including 2.56. The flaw stems from insufficient input sanitization and inadequate output escaping, enabling an unauthenticated attacker to inject any JavaScript payload that will be stored and executed when a user visits the compromised page.
Affected Systems
The vulnerable plugin is distributed by gamerz as WP‑Stats. All versions of WP‑Stats 2.56 or older are impacted; any site installing those releases with WordPress is potentially affected.
Risk and Exploitability
The CVSS score of 7.2 reflects high severity, and the flaw can be exploited without any authentication. Although no EPSS score is available and it is not listed in CISA KEV, the stored nature of the XSS means that once an attacker crafts and submits an injection via any plugin input, the malicious script will run in the browsers of every visitor to that page. The impact is confined to client‑side code execution, which can lead to cookie theft, session hijacking, defacement, or further malware delivery.
OpenCVE Enrichment