Junglewise Threat Intelligence

CVE-2026-84774: WP Statistics unauthenticated cross-site scripting

CVE-2026-84774 · Severity: medium · CVSS 6.1 · Published 2026-09-03

Executive brief

WP Statistics is a popular WordPress plugin used to track and display website analytics and visitor statistics. An unauthenticated attacker can inject malicious scripts into affected versions, allowing them to steal visitor data, hijack user accounts, or compromise website functionality without requiring any authentication or admin access.

Technical details

This vulnerability is a reflected or stored cross-site scripting (XSS) flaw in WP Statistics versions 14.16.11 and earlier that can be exploited without authentication. The vulnerability allows an attacker to inject malicious JavaScript that will execute in the context of visitors' browsers. While the initial attack can be initiated by an unauthenticated attacker, successful exploitation typically requires user interaction (such as a victim clicking a malicious link or visiting a crafted page). The vulnerability has been patched in version 14.16.12 and later, which is available for immediate deployment.

Affected products

  • VeronaLabs WP Statistics <= 14.16.11

Timeline

  • 2026-09-03: disclosed
  • 2026-09-02: patched: Version 14.16.12 and later
  • 2026-08-26: other: Reported by TwinSecKR

References

Related threats