Impact
The WP Statistics plugin contains a reflected cross‑site scripting flaw that is triggered when a specially crafted REQUEST_URI query-parameter key is included in a URL. Because the plugin fails to properly escape or validate this input before rendering it back to the page, an unauthenticated attacker can embed arbitrary JavaScript that will run in the context of any user who loads the page. This flaw can enable session hijacking, credential theft, or defacement, affecting the confidentiality, integrity, and availability of the target WordPress site.
Affected Systems
All versions of WP Statistics released by veronalabs up to and including 14.16.14 are vulnerable. The affected product is the WP Statistics – Simple, privacy‑friendly Google Analytics alternative plugin for WordPress. No other versions or variants are listed in the current advisory.
Risk and Exploitability
With a CVSS score of 6.1, the vulnerability poses a moderate risk. The EPSS score is not available, and the issue is not presently listed in the CISA KEV catalog, suggesting limited known exploitation activity at this time. Attackers can exploit the flaw without any authentication by tricking a victim into visiting a specially crafted URL that contains the malicious query‑parameter key, after which the injected script executes automatically. Because the code runs client‑side, the impact is confined to browsers that load the page, and the attack requires no server‑side compromise or privileged access.
OpenCVE Enrichment