The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload can be planted without authentication via the public /wp-statistics/v2/hit REST endpoint, because the required signature is exposed on the public homepage and a base64-encoded page_uri POST parameter overrides the previously sanitized REQUEST_URI, allowing the malicious utm_campaign value to bypass sanitization and be stored in the database.
References
Link Providers
https://github.com/wp-statistics/wp-statistics/commit/6ab74427778b89c9e88471e9dd7407d9055a9b34 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.7/assets/dev/javascript/helper.js#L267 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.7/includes/api/v2/class-wp-statistics-api-hit.php#L78 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.7/includes/class-wp-statistics-helper.php#L1462 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.7/includes/class-wp-statistics-hits.php#L102 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.7/views/components/tables/referred-visitors.php#L79 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.7/views/components/tables/visitors.php#L94 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.8/assets/dev/javascript/helper.js#L267 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.8/includes/api/v2/class-wp-statistics-api-hit.php#L78 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.8/includes/class-wp-statistics-helper.php#L1462 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.8/includes/class-wp-statistics-hits.php#L102 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.8/views/components/tables/referred-visitors.php#L79 cve-icon cve-icon
https://plugins.trac.wordpress.org/browser/wp-statistics/tags/14.16.8/views/components/tables/visitors.php#L94 cve-icon cve-icon
https://www.wordfence.com/threat-intel/vulnerabilities/id/b5baecfe-ce0b-4cec-8462-bfd7eadd41e9?source=cve cve-icon cve-icon
History

Wed, 19 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Description The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload can be planted without authentication via the public /wp-statistics/v2/hit REST endpoint, because the required signature is exposed on the public homepage and a base64-encoded page_uri POST parameter overrides the previously sanitized REQUEST_URI, allowing the malicious utm_campaign value to bypass sanitization and be stored in the database.
Title WP Statistics <= 14.16.8 - Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-08-19T06:37:54.188Z

Reserved: 2026-07-14T18:46:23.515Z

Link: CVE-2026-15780

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-19T07:16:27.773

Modified: 2026-08-19T07:16:27.773

Link: CVE-2026-15780

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.