WordPress security by component
StatCounter – Free Real Time Visitor Stats
Plugin description
StatCounter – Free Real Time Visitor Stats connects WordPress websites with StatCounter for visitor statistics and analytics.
StatCounter – Free Real Time Visitor Stats (official-statcounter-plugin-for-wordpress) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest published CVSS base score is 6.5.
Plugin slug:
official-statcounter-plugin-for-wordpressLatest vulnerability
CVE-2026-57629: StatCounter: Cross-site scripting
StatCounter is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.1.1.
| Safe version |
|
||
|---|---|---|---|
| Jun 26, 2026 |
CVE-2026-57629
StatCounter: Cross-site scripting
StatCounter is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.1.1.
|
2.1.2 |
CVE6.5
NVDPending
|
| May 29, 2026 |
CVE-2026-6275
StatCounter – Free Real Time Visitor Stats: Cross-site scripting
StatCounter – Free Real Time Visitor Stats is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.1.1.
|
2.1.2 |
CVE6.4
NVDPending
|
| Feb 19, 2026 |
CVE-2025-13048
StatCounter – Free Real Time Visitor Stats: Cross-site scripting
StatCounter – Free Real Time Visitor Stats is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|