« Back to list

Veronalabs

Veronalabs WP Statistics: vulnerabilities and CVEs

Veronalabs WP Statistics has 21 published vulnerabilities, 1 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs21
Last 12 months1
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-48839High (7.1)0.25%—Jun 1, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. This issue affects WP Statistics: from n/a through 14.16.6.
CVE-2025-55716Medium (4.3)0.20%—Aug 14, 2025
Missing Authorization vulnerability in VeronaLabs WP Statistics wp-statistics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Statistics: from n/a through <= 14.15.
CVE-2023-0955High (8.8)0.90%—Mar 27, 2023
The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the…
CVE-2022-38074High (8.8)0.73%—Mar 13, 2023
SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.
CVE-2021-4333Medium (6.5)0.38%—Mar 7, 2023
The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing or incorrect nonce validation on the view() function. This makes it…
CVE-2022-4230High (8.8)36%—Jan 23, 2023
The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the…
CVE-2022-27231Medium (6.1)1.0%—Jun 13, 2022
Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web…
CVE-2022-1005Medium (6.1)0.89%—Jun 8, 2022
The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode…
CVE-2022-25307Medium (6.1)1.4%—Feb 24, 2022
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows…
CVE-2022-25306Medium (6.1)1.4%—Feb 24, 2022
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows…
CVE-2022-25305Medium (6.1)79%—Feb 24, 2022
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers…
CVE-2022-25149High (7.5)77%—Feb 24, 2022
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers…
CVE-2022-25148High (7.5)81%—Feb 24, 2022
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows…
CVE-2022-0651High (7.5)32%—Feb 24, 2022
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which…
CVE-2022-0513High (7.5)53%—Feb 16, 2022
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which…
CVE-2021-24340High (7.5)30%—Jun 7, 2021
The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been…
CVE-2017-18515Critical (9.8)2.5%—Aug 14, 2019
The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.
CVE-2019-13275Critical (9.8)2.6%—Jul 4, 2019
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated…
CVE-2019-12566Medium (5.4)1.1%—Jun 3, 2019
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript,…
CVE-2019-10864Medium (6.1)1.4%—Apr 23, 2019
The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.
CVE-2018-1000556Medium (6.1)0.71%—Jun 26, 2018
WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.007 JavaScript1
  2. T1189 Drive-by Compromise1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Veronalabs