PT-2026-44751 · Statcounter · Statcounter – Free Real Time Visitor Stats
Zast.Ai
·
Published
2026-05-29
·
Updated
2026-05-29
·
CVE-2026-6275
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the statcounter addToTags() function. The function is hooked to wp head and fires on every single post page. It retrieves the post author's nickname via the author meta() and echoes it directly into a JavaScript double-quoted string context inside a
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Statcounter – Free Real Time Visitor Stats