CVE-2026-3488
WP Statistics – Simple, privacy-friendly Google Analytics alternative
Minimum safe version
14.16.5
Update to 14.16.5 or later to address 58 fixable vulnerabilities
CVE-2026-5231
WP Statistics <= 14.5.4 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header
CVE-2025-55716
WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin <= 14.13.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Update
CVE-2024-2194
WP Statistic < 13.1.6 - Reflected Cross-Site Scripting
WP Statistics <= 2.2.4 - Cross-Site Scripting (XSS)
WP Statistics <= 8.3 - Stored & Reflected Cross-Site Scripting (XSS)
WP Statistics <= 8.4 - Unauthenticated Referer Header Stored XSS
WP Statistics <= 9.1.2 - Authenticated Stored Cross-Site Scripting (XSS)
WP Statistics <= 9.4 - Authenticated SQL Injection
WP Statistics <= 9.5.1 - Referer Cross-Site Scripting (XSS)
WP Statistics <= 12.0.8.1 - Authenticated Reflected Cross-Site Scripting (XSS)
WP Statistics <= 12.6.6.1 - Unauthenticated Stored XSS Under Certain Configurations
WP Statistic < 13.1 - Reflected Cross-Site Scripting (XSS)
WordPress WP Statistics Plugin < 14.0 is vulnerable to SQL Injection
CVE-2021-4333
CVE-2022-38074
WP Statistics <= 2.2.4 - Cross-Site Scripting
WP Statistics < 8.3.1 - Multiple Cross-Site Scripting
WP Statistics <= 8.4 - Stored Cross-Site Scripting
WP Statistics < 9.1.3 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Statistics < 9.4.1 - Authenticated Blind SQL Injection
WP Statistics <= 9.5.1 - Cross-Site Scripting
CVE-2022-4230
WP Statistics <= 12.0.8.1 - Reflected Cross-Site Scripting
WP Statistics <= 12.6.6.1 - Unauthenticated Stored Cross-Site Scripting via IP Manipulation
WP Statistics <= 13.0.9 - Reflected Cross-Site Scripting
WP Statistics <= 13.2.5 - Information Disclosure
WP Statistics <= 13.2.5 - Authenticated (Subscriber+) SQL Injection
WordPress WP Statistics Plugin <= 8.4 - Stored XSS
WordPress WP Statistics Plugin <= 8.3 - Stored & Reflected XSS
WordPress WP Statistics Plugin <= 9.1.2 - Stored Cross Site Scripting
WordPress WP Statistics Plugin <= 2.2.4 - Cross Site Scripting
WordPress WP Statistics Plugin <= 9.5.1 - Cross Site Scripting
WordPress WP Statistics Plugin <= 9.4 - SQL Injection
WordPress WP Statistics plugin <=12.0.5 - Reflected Cross-Site Scripting (XSS) vulnerability
WordPress WP Statistics plugin <=12.0.7 - Authenticated SQL Injection vulnerability
CVE-2022-1005
CVE-2022-27231
WordPress WP Statistics plugin <= 12.6.6.1 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability
WordPress WP Statistics plugin <= 13.0.7 - Unauthenticated Time-Based Blind SQL Injection (SQLi) vulnerability
CVE-2017-2136
CVE-2017-2147
CVE-2017-2135
CVE-2017-10991
CVE-2018-1000556
WordPress WP Statistics plugin <= 12.6.3 - Cross-Site Scripting (XSS) vulnerability
WordPress WP Statistics plugin <= 12.6.5 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
CVE-2019-13275
CVE-2017-18515
CVE-2021-24340
CVE-2022-0513
CVE-2022-25307
CVE-2022-25306
CVE-2022-25305
CVE-2022-25149
CVE-2022-25148
CVE-2022-0651