VYPR

Wp Statistics

by WordPress

Source repositories

CVEs (30)

  • CVE-2026-48839HigJun 1, 2026
    risk 0.39cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. This issue affects WP Statistics: from n/a through 14.16.6.

  • CVE-2022-38074HigMar 13, 2023
    risk 0.39cvss 7.1epss 0.01

    SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.

  • CVE-2026-16562MedAug 8, 2026
    risk 0.35cvss 6.5epss 0.00

    The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's…

  • CVE-2026-3488MedApr 17, 2026
    risk 0.35cvss 6.5epss 0.00

    The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing capability checks on multiple AJAX handlers including `wp_statistics_get_filters`, `wp_statistics_getPrivacyStatus`,…

  • CVE-2022-1005MedJun 8, 2022
    risk 0.33cvss 6.1epss 0.01

    The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode characters

  • CVE-2025-3953MedApr 30, 2025
    risk 0.28cvss 5.4epss 0.00

    The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'optionUpdater' function in all versions up to, and including, 14.13.3. This makes it…

  • CVE-2025-55716MedAug 14, 2025
    risk 0.21cvss 4.3epss 0.00

    Missing Authorization vulnerability in VeronaLabs WP Statistics wp-statistics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Statistics: from n/a through <= 14.15.

  • CVE-2019-13275CriJul 4, 2019
    risk 0.00cvss 9.8epss 0.03

    An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.

  • CVE-2019-12566MedJun 3, 2019
    risk 0.00cvss 5.4epss 0.01

    The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.

  • CVE-2019-10864MedApr 23, 2019
    risk 0.00cvss 6.1epss 0.01

    The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.

Page 2 of 2