← WordPress Vulnerabilities
WordPress security by component

StatCounter – Free Real Time Visitor Stats

StatCounter – Free Real Time Visitor Stats connects WordPress websites with StatCounter for visitor statistics and analytics.

StatCounter – Free Real Time Visitor Stats (official-statcounter-plugin-for-wordpress) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest published CVSS base score is 6.5.

Plugin slug: official-statcounter-plugin-for-wordpress

CVE-2026-57629: StatCounter: Cross-site scripting

StatCounter is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.1.1.

PublishedJun 26, 2026
Known safe version2.1.2
Published vulnerabilities for official-statcounter-plugin-for-wordpress
Safe version
Jun 26, 2026 CVE-2026-57629
StatCounter: Cross-site scripting
StatCounter is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 2.1.1.
2.1.2
CVE6.5
NVDPending
May 29, 2026 CVE-2026-6275
StatCounter – Free Real Time Visitor Stats: Cross-site scripting
StatCounter – Free Real Time Visitor Stats is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 2.1.1.
2.1.2
CVE6.4
NVDPending
Feb 19, 2026 CVE-2025-13048
StatCounter – Free Real Time Visitor Stats: Cross-site scripting
StatCounter – Free Real Time Visitor Stats is affected by cross-site scripting. Exploitation requires an authenticated contributor account. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending