PT-2026-78310 · WordPress · Wp Statistics
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Statistics versions prior to 14.16.9
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored Cross-Site Scripting. Attackers can inject arbitrary web scripts that execute when a user accesses an affected page. The injection is possible via the
/wp-statistics/v2/hit REST endpoint, where a base64-encoded page uri POST parameter overrides the sanitized REQUEST URI, enabling a malicious utm campaign value to bypass security checks and be stored in the database. This is facilitated by the fact that the required signature is exposed on the public homepage.Recommendations
Update to a version newer than 14.16.8.
Restrict access to the
/wp-statistics/v2/hit REST endpoint to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Statistics