Junglewise Threat Intelligence

CVE-2026-48839: VeronaLabs WP Statistics DOM-based XSS

CVE-2026-48839 · Severity: high · CVSS 7.1 · Published 2026-06-01

Executive brief

WP Statistics is a popular WordPress plugin used to track and analyze visitor data. A security vulnerability in this plugin could allow an attacker to inject malicious scripts into the website's interface. If an administrator or visitor views a compromised page, the attacker could potentially steal session information, redirect users to malicious sites, or perform unauthorized actions on the website.

Technical details

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the VeronaLabs WP Statistics plugin for WordPress due to improper neutralization of input during web page generation. The flaw affects versions up to and including 14.16.6. An unauthenticated attacker can exploit this by tricking a user into interacting with a specially crafted link or page, leading to the execution of arbitrary JavaScript in the context of the victim's browser. This can result in session hijacking or unauthorized administrative actions if the victim is a site administrator. The issue is resolved in version 14.16.7.

Affected products

  • VeronaLabs WP Statistics up to 14.16.6

Timeline

  • 2026-04-16: other: Reported by researcher daroo
  • 2026-06-01: advisory: Published by Patchstack and NVD
  • 2026-06-01: patched: Fixed in version 14.16.7

References

Related threats