Impact
A vulnerability in the StatCounter WordPress plugin allows a contributor to inject malicious scripts into web pages, enabling an attacker to execute arbitrary code in the browsers of site visitors. This type of Cross Site Scripting flaw can lead to theft of session cookies, defacement of the site, or delivery of malware. The weakness is identified as CWE‑79.
Affected Systems
The StatCounter plugin for WordPress, versions 2.1.1 and earlier, is affected. Users of these versions should verify their plugin version and consider upgrading if a newer release is available.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is client‑side script injection, the attack vector is likely through any user‑controlled input or data that the plugin renders without proper sanitization. An attacker with the ability to input data through the plugin's interfaces could trick users into executing malicious code by visiting affected pages.
OpenCVE Enrichment