Wp-statistics
Wp-statistics WP Statistics: vulnerabilidades y CVE
Wp-statistics WP Statistics tiene 13 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE13
Últimos 12 meses7
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-97652 | Media (6.1) | 0.46% | — | 2 oct 2026 | The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key in all versions up to, and including,… |
| CVE-2026-93770 | Alta (7.1) | 0.20% | — | 30 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions. |
| CVE-2026-84774 | Media (6.1) | 0.25% | — | 3 sept 2026 | Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions. |
| CVE-2026-15780 | Alta (7.2) | 0.65% | — | 19 ago 2026 | The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8… |
| CVE-2026-16562 | Media (6.5) | 0.37% | — | 8 ago 2026 | The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with… |
| CVE-2026-5231 | Alta (7.2) | 0.42% | — | 17 abr 2026 | The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and including, 14.16.4. This is due to insufficient input sanitization and output… |
| CVE-2026-3488 | Media (6.5) | 0.44% | — | 17 abr 2026 | The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing capability checks on multiple AJAX handlers including… |
| CVE-2025-9816 | Alta (7.2) | 9.7% | — | 27 sept 2025 | The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent Header in all versions up to, and including, 14.5.4 due to… |
| CVE-2025-3953 | Media (5.4) | 0.27% | — | 30 abr 2025 | The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'optionUpdater' function in all… |
| CVE-2024-2194 | Alta (7.2) | 68% | — | 13 mar 2024 | The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping.… |
| CVE-2017-10991 | Media (6.1) | 0.76% | — | 7 jul 2017 | The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page. |
| CVE-2017-2147 | Media (6.1) | 1.3% | — | 28 abr 2017 | Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
| CVE-2017-2135 | Media (6.1) | 1.7% | — | 28 abr 2017 | Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.