« Volver al listado

Wp-statistics

Wp-statistics WP Statistics: vulnerabilidades y CVE

Wp-statistics WP Statistics tiene 13 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE13
Últimos 12 meses7
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-97652Media (6.1)0.46%—2 oct 2026
The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key in all versions up to, and including,…
CVE-2026-93770Alta (7.1)0.20%—30 sept 2026
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.
CVE-2026-84774Media (6.1)0.25%—3 sept 2026
Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
CVE-2026-15780Alta (7.2)0.65%—19 ago 2026
The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8…
CVE-2026-16562Media (6.5)0.37%—8 ago 2026
The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with…
CVE-2026-5231Alta (7.2)0.42%—17 abr 2026
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and including, 14.16.4. This is due to insufficient input sanitization and output…
CVE-2026-3488Media (6.5)0.44%—17 abr 2026
The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing capability checks on multiple AJAX handlers including…
CVE-2025-9816Alta (7.2)9.7%—27 sept 2025
The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent Header in all versions up to, and including, 14.5.4 due to…
CVE-2025-3953Media (5.4)0.27%—30 abr 2025
The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'optionUpdater' function in all…
CVE-2024-2194Alta (7.2)68%—13 mar 2024
The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL search parameter in all versions up to, and including, 14.5 due to insufficient input sanitization and output escaping.…
CVE-2017-10991Media (6.1)0.76%—7 jul 2017
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.
CVE-2017-2147Media (6.1)1.3%—28 abr 2017
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2017-2135Media (6.1)1.7%—28 abr 2017
Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript5
  2. T1190 Exploit Public-Facing Application3
  3. T1189 Drive-by Compromise2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.