WordPress security by component
WP Statistics
Plugin description
WP Statistics is a WordPress component with 27 published CVE records in this archive. The latest tracked vulnerability was published Jun 01, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
wp-statisticsLatest vulnerability
CVE-2026-48839: WP Statistics: Cross-site scripting
WP Statistics is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 14.16.6.
| Safe version |
|
||
|---|---|---|---|
| Jun 01, 2026 |
CVE-2026-48839
WP Statistics: Cross-site scripting
WP Statistics is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 14.16.6.
|
14.16.7 |
CVE7.1
NVDPending
|
| Apr 17, 2026 |
CVE-2026-5231
WP Statistics – Simple, privacy-friendly Google Analytics alternative: Cross-site scripting
WP Statistics – Simple, privacy-friendly Google Analytics alternative is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 14.16.4.
|
> 14.16.4 |
CVE7.2
NVDPending
|
| Apr 17, 2026 |
CVE-2026-3488
WP Statistics – Simple, privacy-friendly Google Analytics alternative: A security weakness
WP Statistics – Simple, privacy-friendly Google Analytics alternative is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 14.16.4.
|
> 14.16.4 |
CVE6.5
NVDPending
|
| Sep 27, 2025 |
CVE-2025-9816
WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin: Cross-site scripting
WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Aug 14, 2025 |
CVE-2025-55716
WP Statistics: A security weakness
WP Statistics is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 30, 2025 |
CVE-2025-3953
WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin: A security weakness
WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Mar 13, 2024 |
CVE-2024-2194
WP Statistics: Cross-site scripting
WP Statistics is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Mar 27, 2023 |
CVE-2023-0955
WP Statistics: SQL injection
WP Statistics is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Mar 13, 2023 |
CVE-2022-38074
Wp Statistics: SQL injection
Wp Statistics is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.1
NVD8.8
|
| Mar 07, 2023 |
CVE-2021-4333
WP Statistics: Cross-site request forgery
WP Statistics is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Jan 23, 2023 |
CVE-2022-4230
WP Statistics: SQL injection
WP Statistics is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Jun 13, 2022 |
CVE-2022-27231
Wp Statistics: Cross-site scripting
Wp Statistics is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jun 08, 2022 |
CVE-2022-1005
WP Statistics: Cross-site scripting
WP Statistics is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Feb 24, 2022 |
CVE-2022-25307
WP Statistics: Cross-site scripting
WP Statistics is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Feb 24, 2022 |
CVE-2022-25306
WP Statistics: Cross-site scripting
WP Statistics is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Feb 24, 2022 |
CVE-2022-25305
WP Statistics: Cross-site scripting
WP Statistics is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.2
NVD6.1
|
| Feb 24, 2022 |
CVE-2022-25149
WP Statistics: SQL injection
WP Statistics is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD7.5
|
| Feb 24, 2022 |
CVE-2022-25148
WP Statistics: SQL injection
WP Statistics is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD7.5
|
| Feb 24, 2022 |
CVE-2022-0651
WP Statistics: SQL injection
WP Statistics is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD7.5
|
| Feb 16, 2022 |
CVE-2022-0513
WP Statistics: SQL injection
WP Statistics is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD7.5
|
| Jun 07, 2021 |
CVE-2021-24340
WP Statistics: A security weakness
WP Statistics is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Aug 14, 2019 |
CVE-2017-18515
Wp Statistics: SQL injection
Wp Statistics is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Jul 04, 2019 |
CVE-2019-13275
Wp Statistics: SQL injection
Wp Statistics is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Jun 03, 2019 |
CVE-2019-12566
Wp Statistics: Cross-site scripting
Wp Statistics is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Apr 23, 2019 |
CVE-2019-10864
Wp Statistics: Cross-site scripting
Wp Statistics is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jun 26, 2018 |
CVE-2018-1000556
Wp Statistics: Cross-site scripting
Wp Statistics is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Jul 07, 2017 |
CVE-2017-10991
Wp Statistics: Cross-site scripting
Wp Statistics is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|