Executive brief
The StatCounter plugin for WordPress, which provides website traffic analytics, contains a security flaw that allows users with 'Author' permissions to inject malicious scripts into the website. These scripts can then execute in the browsers of any visitor who views a post written by that author. This could lead to unauthorized actions being performed on behalf of visitors or the theft of sensitive session information.
Technical details
The StatCounter plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'statcounter_addToTags()' function in versions up to 2.1.1. The vulnerability exists because the plugin retrieves the post author's nickname using 'the_author_meta()' and echoes it directly into a JavaScript double-quoted string context within a <script> block without proper escaping (e.g., using 'esc_js()'). An authenticated attacker with Author-level privileges or higher can exploit this by setting their nickname to a malicious script. This script will then execute in the context of any user's browser, including unauthenticated visitors, whenever they access a post authored by the attacker. The issue is addressed in version 2.1.2.
Affected products
- StatCounter StatCounter – Free Real Time Visitor Stats Up to, and including, 2.1.1
Timeline
- 2026-05-29: disclosed
- 2026-05-29: advisory
References
- https://plugins.trac.wordpress.org/browser/official-statcounter-plugin-for-wordpress/tags/2.1.1/StatCounter-Wordpress-Plugin.php
- https://plugins.trac.wordpress.org/browser/official-statcounter-plugin-for-wordpress/tags/2.1.1/StatCounter-Wordpress-Plugin.php
- https://plugins.trac.wordpress.org/browser/official-statcounter-plugin-for-wordpress/trunk/StatCounter-Wordpress-Plugin.php
- https://plugins.trac.wordpress.org/browser/official-statcounter-plugin-for-wordpress/trunk/StatCounter-Wordpress-Plugin.php
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fofficial-statcounter-plugin-for-wordpress/tags/2.1.1&new_path=%2Fofficial-statcounter-plugin-for-wordpress/tags/2.1.2
- https://www.wordfence.com/threat-intel/vulnerabilities/id/30e0bf40-7f7b-43e6-8439-6dc00a889344?source=cve