PT-2025-41675 · WordPress · Easy Plugin Stats

+1

·

CVE-2025-7652

·

Published

2025-10-11

·

Updated

2025-10-11

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Easy Plugin Stats versions prior to 2.0.2
Description The Easy Plugin Stats plugin for WordPress has a flaw that allows malicious code to be stored and executed when a user views a page containing the injected code. This is due to a lack of proper sanitization and escaping of user-provided information within the 'eps' shortcode. An attacker with contributor-level access or higher can inject arbitrary web scripts into pages. These scripts will then run when any user accesses the affected page.
Recommendations Update Easy Plugin Stats to version 2.0.2 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7652

Affected Products

Easy Plugin Stats