Unrated severityNVD Advisory· Published Jul 31, 2026· Updated Jul 31, 2026
NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget
CVE-2026-14845
Description
The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in one of its widgets, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against users viewing the affected widget.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/da5936d2-a96f-4ff8-8562-1248734f577f/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.