Official Statcounter Plugin For Wordpress
by WordPress
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-6275 | Med | 0.42 | 6.4 | 0.00 | May 29, 2026 | The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the statcounter_addToTags() function. The… | ||
| CVE-2026-57629 | Med | 0.00 | 6.5 | 0.00 | Jun 26, 2026 | Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions. |
- risk 0.42cvss 6.4epss 0.00
The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the statcounter_addToTags() function. The…
- risk 0.00cvss 6.5epss 0.00
Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.