Back

HIGH

WP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via platform

Published Feb 24, 2022

Description

The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to and including 13.1.5.

Affected products

Remediation

Vendor solution

Update to version 13.1.6 or newer.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Feb 24, 2022
Updated Feb 7, 2025
Reserved Feb 17, 2022
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a