Medium severity6.1OSV Advisory· Published Apr 23, 2019· Updated Jun 17, 2026
CVE-2019-10864
CVE-2019-10864
Description
The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 12.0.10, 12.0.11, 12.0.12, …
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.