PT-2025-41675 · WordPress · Easy Plugin Stats

Dj

+1

·

Published

2025-10-11

·

Updated

2025-10-11

·

CVE-2025-7652

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Easy Plugin Stats versions prior to 2.0.2
Description The Easy Plugin Stats plugin for WordPress has a flaw that allows malicious code to be stored and executed when a user views a page containing the injected code. This is due to a lack of proper sanitization and escaping of user-provided information within the 'eps' shortcode. An attacker with contributor-level access or higher can inject arbitrary web scripts into pages. These scripts will then run when any user accesses the affected page.
Recommendations Update Easy Plugin Stats to version 2.0.2 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-7652

Affected Products

Easy Plugin Stats