VYPR

WP-Stats

by WordPress

CVEs (3)

  • CVE-2026-19794HigAug 14, 2026
    risk 0.47cvss 7.2epss 0.00

    The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…

  • CVE-2026-66426HigAug 13, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.

  • CVE-2015-10001MedNov 1, 2021
    risk 0.28cvss 4.3epss 0.00

    The WP-Stats WordPress plugin before 2.52 does not have CSRF check when saving its settings, and did not escape some of them when outputting them, allowing attacker to make logged in high privilege users change them and set Cross-Site Scripting payloads