PT-2026-44751 · Statcounter · Statcounter – Free Real Time Visitor Stats

Zast.Ai

·

Published

2026-05-29

·

Updated

2026-05-29

·

CVE-2026-6275

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the statcounter addToTags() function. The function is hooked to wp head and fires on every single post page. It retrieves the post author's nickname via the author meta() and echoes it directly into a JavaScript double-quoted string context inside a

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-6275

Affected Products

Statcounter – Free Real Time Visitor Stats