Description
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
Published: 2026-09-03
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross Site Scripting
Action: Patch Now
AI Analysis

Impact

Unauthenticated Cross Site Scripting is present in the WordPress WP Statistics plugin versions 14.16.11 and earlier. This is a CWE-79 vulnerability. By sending crafted input that is not validated or sanitized, an attacker can inject arbitrary client‑side scripts that execute in the browser of any visitor. This can lead to session hijacking, defacement, data theft, or propagation of further attacks through the compromised site.

Affected Systems

The vulnerability affects the VeronaLabs WP Statistics plugin. All installations running version 14.16.11 or older are impacted. Upgrading to 14.16.12 or newer mitigates the issue.

Risk and Exploitability

The CVSS score of 6.1 indicates a medium severity risk; the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw through any input field that accepts data without proper filtering, typically via unauthenticated access to plugin management pages or exposed endpoints. The impact is confined to client browsers and does not affect the server state directly.

Generated by OpenCVE AI on September 3, 2026 at 20:33 UTC.

Remediation

Vendor Solution

Update the WordPress WP Statistics Plugin to the latest available version (at least 14.16.12).


OpenCVE Recommended Actions

  • Upgrade the WordPress WP Statistics Plugin to version 14.16.12 or later
  • Disable or remove any remaining instances of the older WP Statistics plugin to eliminate the vulnerable code path
  • Regularly scan the site for other outdated plugins and address or patch identified XSS or input handling weaknesses

Generated by OpenCVE AI on September 3, 2026 at 20:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 05 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Veronalabs
Veronalabs wp Statistics
Wordpress
Wordpress wordpress
Vendors & Products Veronalabs
Veronalabs wp Statistics
Wordpress
Wordpress wordpress

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
Title WordPress WP Statistics plugin <= 14.16.11 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Veronalabs Wp Statistics
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-05T01:52:15.766Z

Reserved: 2026-09-02T09:57:48.859Z

Link: CVE-2026-84774

cve-icon Vulnrichment

Updated: 2026-09-05T01:52:11.815Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:28.383

Modified: 2026-09-05T02:17:18.323

Link: CVE-2026-84774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:45:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')