WordPress security by component
NewStatPress
Plugin description
NewStatPress is a WordPress component with 10 published CVE records in this archive. The latest tracked vulnerability was published Dec 12, 2025; the highest CVE/CNA score is 9.8.
Plugin slug:
newstatpressLatest vulnerability
CVE-2025-13747: NewStatPress: Cross-site scripting
NewStatPress is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
| Safe version |
|
||
|---|---|---|---|
| Dec 12, 2025 |
CVE-2025-13747
NewStatPress: Cross-site scripting
NewStatPress is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Feb 14, 2022 |
CVE-2022-0206
NewStatPress: Cross-site scripting
NewStatPress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 22, 2019 |
CVE-2017-18575
Newstatpress: Cross-site scripting
Newstatpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 14, 2019 |
CVE-2015-9315
Newstatpress: SQL injection
Newstatpress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Aug 14, 2019 |
CVE-2015-9314
Newstatpress: Cross-site scripting
Newstatpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 14, 2019 |
CVE-2015-9313
Newstatpress: SQL injection
Newstatpress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Aug 14, 2019 |
CVE-2015-9312
Newstatpress: Cross-site scripting
Newstatpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Aug 14, 2019 |
CVE-2015-9311
Newstatpress: Cross-site scripting
Newstatpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| May 27, 2015 |
CVE-2015-4063
Newstatpress: Cross-site scripting
Newstatpress is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE3.5
NVD3.5
|
| May 27, 2015 |
CVE-2015-4062
Newstatpress: SQL injection
Newstatpress is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.5
NVD6.5
|