Impact
Unauthenticated Cross Site Scripting is present in the WordPress WP Statistics plugin versions 14.16.11 and earlier. This is a CWE-79 vulnerability. By sending crafted input that is not validated or sanitized, an attacker can inject arbitrary client‑side scripts that execute in the browser of any visitor. This can lead to session hijacking, defacement, data theft, or propagation of further attacks through the compromised site.
Affected Systems
The vulnerability affects the VeronaLabs WP Statistics plugin. All installations running version 14.16.11 or older are impacted. Upgrading to 14.16.12 or newer mitigates the issue.
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity risk; the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw through any input field that accepts data without proper filtering, typically via unauthenticated access to plugin management pages or exposed endpoints. The impact is confined to client browsers and does not affect the server state directly.
OpenCVE Enrichment