Description
The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key in all versions up to, and including, 14.16.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Published: 2026-10-02
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side script injection via reflected XSS
Action: Patch Now
AI Analysis

Impact

The WP Statistics plugin contains a reflected cross‑site scripting flaw that is triggered when a specially crafted REQUEST_URI query-parameter key is included in a URL. Because the plugin fails to properly escape or validate this input before rendering it back to the page, an unauthenticated attacker can embed arbitrary JavaScript that will run in the context of any user who loads the page. This flaw can enable session hijacking, credential theft, or defacement, affecting the confidentiality, integrity, and availability of the target WordPress site.

Affected Systems

All versions of WP Statistics released by veronalabs up to and including 14.16.14 are vulnerable. The affected product is the WP Statistics – Simple, privacy‑friendly Google Analytics alternative plugin for WordPress. No other versions or variants are listed in the current advisory.

Risk and Exploitability

With a CVSS score of 6.1, the vulnerability poses a moderate risk. The EPSS score is not available, and the issue is not presently listed in the CISA KEV catalog, suggesting limited known exploitation activity at this time. Attackers can exploit the flaw without any authentication by tricking a victim into visiting a specially crafted URL that contains the malicious query‑parameter key, after which the injected script executes automatically. Because the code runs client‑side, the impact is confined to browsers that load the page, and the attack requires no server‑side compromise or privileged access.

Generated by OpenCVE AI on October 2, 2026 at 10:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WP Statistics plugin to version 14.16.15 or later, which removes the unsanitized reflection of the REQUEST_URI query-parameter key.
  • If an upgrade is not immediately possible, implement a temporary filter to sanitize the query‑parameter key before it is processed—using functions such as sanitize_text_field or esc_html—so that any malicious characters are neutralized.
  • Deploy a web application firewall or similar runtime protection to detect and block suspicious request patterns that attempt to use query‑parameter keys to inject scripts.

Generated by OpenCVE AI on October 2, 2026 at 10:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Description The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key in all versions up to, and including, 14.16.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Title WP Statistics <= 14.16.14 - Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T09:25:57.902Z

Reserved: 2026-09-24T19:09:15.550Z

Link: CVE-2026-97652

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T10:17:10.163

Modified: 2026-10-02T13:18:55.613

Link: CVE-2026-97652

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T10:30:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')