Impact
The vulnerability allows an unauthenticated attacker to inject arbitrary script into pages generated by WP-Stats, enabling client‐side attacks such as defacement, cookie theft or redirection. The defect is an input validation flaw classified as CWE‑79, leading to moderate‑to‑high risk of data exposure or session compromise.
Affected Systems
WP‑Stats plugin for WordPress, developed by Lester Chan, in all versions up to and including 2.56.
Risk and Exploitability
The CVSS score of 7.1 signals a high severity. No EPSS data is available and the vulnerability is not listed in the CISA KEV catalog. While the official description does not detail the precise attack vector, the fact that the flaw is unauthenticated suggests that any web user who can access a page that renders data from WP‑Stats could trigger the exploit. The lack of mitigation from the plugin itself means attackers can directly inject JavaScript without prior exploitation of another component.
OpenCVE Enrichment