PT-2026-33395 · WordPress · Wp Statistics
Daroo
·
Published
2026-04-17
·
Updated
2026-04-22
·
CVE-2026-5231
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Statistics versions prior to 14.16.5
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. The referral parser copies the raw value of the 'utm source' parameter into the
source name field when a wildcard channel domain matches. Subsequently, the chart renderer inserts this value into legend markup via innerHTML without escaping. This allows unauthenticated attackers to inject arbitrary web scripts into admin pages, which execute when an administrator accesses the Referrals Overview or Social Media analytics pages. Real-world incidents of this issue being exploited have been reported.Recommendations
Update to a version newer than 14.16.4.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Statistics