Veronalabs

Wp Statistics

30 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 04.10.2026 07:00:43
  • Zuletzt bearbeitet 06.10.2026 15:04:25

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics allows Reflected XSS.This issue affects WP Statistics: from n/a through 14.16.14.

  • EPSS 0.26%
  • Veröffentlicht 02.10.2026 09:25:57
  • Zuletzt bearbeitet 03.10.2026 16:16:49

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via REQUEST_URI Query-Parameter Key in all versions up to, and including, 14.16.14 due to insufficient inpu...

  • EPSS 0.2%
  • Veröffentlicht 30.09.2026 12:26:55
  • Zuletzt bearbeitet 30.09.2026 14:17:36

Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.13 versions.

  • EPSS 0.15%
  • Veröffentlicht 03.09.2026 16:31:53
  • Zuletzt bearbeitet 05.09.2026 02:17:18

Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.

  • EPSS 0.39%
  • Veröffentlicht 19.08.2026 06:37:54
  • Zuletzt bearbeitet 20.08.2026 12:48:10

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanit...

  • EPSS 0.21%
  • Veröffentlicht 01.06.2026 14:43:29
  • Zuletzt bearbeitet 22.07.2026 07:10:00

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. This issue affects WP Statistics: from n/a through 14.16.6.

  • EPSS 0.48%
  • Veröffentlicht 17.04.2026 01:24:37
  • Zuletzt bearbeitet 22.04.2026 20:22:50

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and including, 14.16.4. This is due to insufficient input sanitization and output escaping. The plugin's referra...

  • EPSS 0.31%
  • Veröffentlicht 17.04.2026 01:24:37
  • Zuletzt bearbeitet 22.04.2026 20:22:50

The WP Statistics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14.16.4. This is due to missing capability checks on multiple AJAX handlers including `wp_statistics_get_filters`, `wp_statistics_getP...

  • EPSS 9.05%
  • Veröffentlicht 27.09.2025 05:15:30
  • Zuletzt bearbeitet 15.04.2026 00:35:42

The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent Header in all versions up to, and including, 14.5.4 due to insufficient input sanitization and...

  • EPSS 0.19%
  • Veröffentlicht 14.08.2025 18:21:23
  • Zuletzt bearbeitet 23.04.2026 15:32:56

Missing Authorization vulnerability in VeronaLabs WP Statistics wp-statistics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Statistics: from n/a through <= 14.15.