The Matomo Analytics – Ethical Stats. Powerful Insights. plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the idsite parameter in all versions up to, and including, 4.15.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Matomo <= 4.15.3 - Reflected Cross-Site Scripting via idsite |
Tue, 01 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Matomo
Matomo matomo |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:matomo:matomo:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Matomo
Matomo matomo |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:44:20.708Z
Reserved: 2023-12-18T15:12:38.158Z
Link: CVE-2023-6923
Updated: 2024-08-02T08:42:08.402Z
Status : Modified
Published: 2024-02-29T01:42:49.007
Modified: 2026-04-08T17:17:17.177
Link: CVE-2023-6923
No data.
OpenCVE Enrichment
No data.