Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WP Statistics — Vulnerabilities & Security Advisories 18

All 18 CVE vulnerabilities found in WP Statistics, with AI-generated Chinese analysis, references, and POCs.

This page documents known weaknesses associated with WP Statistics, a widely used WordPress plugin that provides detailed web analytics. The aggregation here focuses on Common Weakness Enumerations and related security flaws that have been identified in this specific software component, covering historical and recent disclosures. By centralizing this data, the page allows security professionals and administrators to efficiently track vendor advisories and monitor the evolution of reported issues within the WP Statistics ecosystem. Users can also gain a deeper understanding of the specific weakness classes that frequently affect this type of WordPress plugin, helping to contextualize the risks based on common architectural patterns or configuration errors. Furthermore, this resource serves as a historical record, enabling teams to look up a product's vulnerability timeline and assess its long-term security posture. This information is critical for maintaining site integrity, as WordPress plugins often serve as entry points for attackers seeking to exploit server-side vulnerabilities. The data presented is compiled from various sources to provide a comprehensive view of the threat landscape specific to WP Statistics. It does not include exhaustive technical details for every single issue but rather highlights the significant findings that warrant attention during patch management or security audits. This approach ensures that stakeholders have access to the most relevant information needed to make informed decisions about updating, configuring, or potentially replacing the plugin to mitigate potential risks associated with these identified weaknesses.

Vendor: WP Statistics

CVE IDTitleCVSSSeverityPublished
CVE-2026-48839 WordPress WP Statistics plugin <= 14.16.6 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2026-06-01
CVE-2025-55716 WordPress WP Statistics Plugin <= 14.15 - Broken Access Control Vulnerability CWE-862 4.3 Medium2025-08-14
CVE-2023-0955 WP Statistics < 14.0 - Authenticated SQLi 8.8 -2023-03-27
CVE-2022-38074 WordPress WP Statistics Plugin <= 13.2.10 is vulnerable to SQL Injection CWE-89 9.9 High2023-03-13
CVE-2022-4230 WP Statistics < 13.2.9 - Authenticated SQLi 8.8 -2023-01-23
CVE-2022-27231 WordPress plugin WP Statistics 跨站脚本漏洞 6.1 -2022-06-13
CVE-2022-1005 WP Statistics < 13.2.2 - Reflected Cross-Site Scripting CWE-79 6.1 -2022-06-06
CVE-2022-25307 WP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via platform CWE-79 7.2 High2022-02-24
CVE-2022-25305 WP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via IP CWE-79 7.2 High2022-02-24
CVE-2022-25306 WP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via browser CWE-79 7.2 High2022-02-24
CVE-2022-25149 WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via IP CWE-89 9.8 Critical2022-02-24
CVE-2022-0651 WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via current_page_type CWE-89 9.8 Critical2022-02-24
CVE-2022-25148 WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via current_page_id CWE-89 9.8 Critical2022-02-24
CVE-2022-0513 WP Statistics <= 13.1.4 Unauthenticated Blind SQL Injection via exclusion_reason CWE-89 9.8 Critical2022-02-16
CVE-2021-24340 WP Statistics < 13.0.8 - Unauthenticated SQL Injection CWE-89 7.5 -2021-06-07
CVE-2017-2135 WordPress WP Statistics 跨站脚本漏洞 6.1 -2017-04-28
CVE-2017-2147 WordPress WP Statistics 跨站脚本漏洞 6.1 -2017-04-28
CVE-2017-2136 WordPress WP Statistics 跨站脚本漏洞 6.1 -2017-04-28

All 18 known CVE vulnerabilities affecting WP Statistics with full Chinese analysis, references, and POCs where available.