Veronalabs
Veronalabs WP Statistics: vulnerabilities and CVEs
Veronalabs WP Statistics has 21 published vulnerabilities, 1 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs21
Last 12 months1
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48839 | High (7.1) | 0.25% | — | Jun 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. This issue affects WP Statistics: from n/a through 14.16.6. |
| CVE-2025-55716 | Medium (4.3) | 0.20% | — | Aug 14, 2025 | Missing Authorization vulnerability in VeronaLabs WP Statistics wp-statistics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Statistics: from n/a through <= 14.15. |
| CVE-2023-0955 | High (8.8) | 0.90% | — | Mar 27, 2023 | The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the… |
| CVE-2022-38074 | High (8.8) | 0.73% | — | Mar 13, 2023 | SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions. |
| CVE-2021-4333 | Medium (6.5) | 0.38% | — | Mar 7, 2023 | The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing or incorrect nonce validation on the view() function. This makes it… |
| CVE-2022-4230 | High (8.8) | 36% | — | Jan 23, 2023 | The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the… |
| CVE-2022-27231 | Medium (6.1) | 1.0% | — | Jun 13, 2022 | Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web… |
| CVE-2022-1005 | Medium (6.1) | 0.89% | — | Jun 8, 2022 | The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode… |
| CVE-2022-25307 | Medium (6.1) | 1.4% | — | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows… |
| CVE-2022-25306 | Medium (6.1) | 1.4% | — | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows… |
| CVE-2022-25305 | Medium (6.1) | 79% | — | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers… |
| CVE-2022-25149 | High (7.5) | 77% | — | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers… |
| CVE-2022-25148 | High (7.5) | 81% | — | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows… |
| CVE-2022-0651 | High (7.5) | 32% | — | Feb 24, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which… |
| CVE-2022-0513 | High (7.5) | 53% | — | Feb 16, 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which… |
| CVE-2021-24340 | High (7.5) | 30% | — | Jun 7, 2021 | The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been… |
| CVE-2017-18515 | Critical (9.8) | 2.5% | — | Aug 14, 2019 | The wp-statistics plugin before 12.0.8 for WordPress has SQL injection. |
| CVE-2019-13275 | Critical (9.8) | 2.6% | — | Jul 4, 2019 | An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated… |
| CVE-2019-12566 | Medium (5.4) | 1.1% | — | Jun 3, 2019 | The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript,… |
| CVE-2019-10864 | Medium (6.1) | 1.4% | — | Apr 23, 2019 | The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request. |
| CVE-2018-1000556 | Medium (6.1) | 0.71% | — | Jun 26, 2018 | WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.