PT-2026-78310 · WordPress · Wp Statistics

·

CVE-2026-15780

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP Statistics versions prior to 14.16.9
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting. Attackers can inject arbitrary web scripts that execute when a user accesses an affected page. The injection is possible via the /wp-statistics/v2/hit REST endpoint, where a base64-encoded page uri POST parameter overrides the sanitized REQUEST URI, enabling a malicious utm campaign value to bypass security checks and be stored in the database. This is facilitated by the fact that the required signature is exposed on the public homepage.
Recommendations Update to a version newer than 14.16.8. Restrict access to the /wp-statistics/v2/hit REST endpoint to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15780

Affected Products

Wp Statistics