PT-2026-33395 · WordPress · Wp Statistics

Daroo

·

Published

2026-04-17

·

Updated

2026-04-22

·

CVE-2026-5231

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Statistics versions prior to 14.16.5
Description Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. The referral parser copies the raw value of the 'utm source' parameter into the source name field when a wildcard channel domain matches. Subsequently, the chart renderer inserts this value into legend markup via innerHTML without escaping. This allows unauthenticated attackers to inject arbitrary web scripts into admin pages, which execute when an administrator accesses the Referrals Overview or Social Media analytics pages. Real-world incidents of this issue being exploited have been reported.
Recommendations Update to a version newer than 14.16.4.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-5231

Affected Products

Wp Statistics