Sceawere

Vulnerability Detail

CVE-2026-97276UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Statistics Reflected XSS

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
4h ago
Vendor
VeronaLabs
Product
WP Statistics
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics wp-statistics allows Reflected XSS.This issue affects WP Statistics: from n/a through 14.16.14.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-10-04T09:16:39.640Z",
  "pubdate": "2026-10-04T09:16:39.640Z",
  "executiveSummary": "The WP Statistics plugin for WordPress contains a Reflected Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation.\nThis vulnerability, affecting versions from n/a through 14.16.14, allows remote, unauthenticated attackers to inject malicious JavaScript into web pages viewed by other users.\nThe flaw stems from the application's failure to adequately sanitize or encode input before reflecting it back to the browser.\nExploitation enables attackers to execute arbitrary scripts in the context of the victim's session, potentially leading to unauthorized actions, session hijacking, or the theft of sensitive session cookies.\nThe risk is significant for administrators and users interacting with the affected WordPress installation, as the exploitation does not require advanced access but relies on the victim visiting a crafted URL containing the malicious payload.",
  "technicalDetails": "The vulnerability is classified as CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').\nThe root cause of this Reflected XSS vulnerability lies within the plugin's handling of HTTP request parameters. The WP Statistics plugin processes input directly from the URL query string and fails to perform adequate context-aware output encoding or input validation before reflecting this data back to the user's browser within the generated HTML response.\nWhen an attacker crafts a malicious URL containing a JavaScript payload within the vulnerable parameter, the application embeds this payload directly into the server response. When a victim clicks this link or navigates to the URL, the browser interprets the injected script as legitimate code originating from the trusted domain.\nThe attack flow proceeds as follows: 1. The attacker identifies the vulnerable parameter within the WP Statistics plugin which is not properly sanitized. 2. The attacker constructs a malicious URL incorporating a JavaScript payload into that parameter. 3. The attacker baits an authenticated user or administrator into clicking the link. 4. The server receives the request, processes the malicious input, and reflects the script in the subsequent HTTP response. 5. The victim's browser executes the script in the context of the WordPress site session.\nBecause the payload executes within the security context of the victim's session, it inherits the victim's privileges. If the victim is an administrator, the attacker can execute administrative actions via XHR or Fetch requests, create new admin accounts, modify plugin settings, or exfiltrate sensitive data such as CSRF tokens or session cookies.\nThe vulnerability is present in the WP Statistics plugin from version n/a through 14.16.14. It is accessible via the network and does not require pre-existing authentication for the attacker, although the success of the attack is dependent on the victim's interaction with the malicious link.\nThe lack of Content Security Policy (CSP) headers or robust output encoding mechanisms exacerbates the impact of this injection flaw, allowing for persistent or semi-persistent malicious script execution depending on the specific reflection point in the plugin's UI."
}
CVE-2026-97276: WP Statistics Reflected XSS (HIGH Severity, CVSS: 7.1) | Sceawere