VYPR

StatCounter

by WordPress

CVEs (2)

  • CVE-2026-6275MedMay 29, 2026
    risk 0.42cvss 6.4epss

    The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the statcounter_addToTags() function. The…

  • CVE-2021-24920Feb 28, 2022
    risk 0.00cvss epss 0.00

    The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed