Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5231

27
FAUCET Score

OVERVIEW CVE-2026-5231 is a stored cross-site scripting (XSS) vulnerability in the WP Statistics plugin for WordPress, affecting all versions up to and including 14.16.4. The flaw exists in the plugin's referral parser and chart rendering functionality, where the utm_source parameter is insufficiently sanitized and later inserted into admin page markup without proper output escaping. This allows unauthenticated attackers to inject malicious scripts that execute in administrator sessions. SEVERITY The vulnerability carries a CVSS score of 7.2 (HIGH) with a network-based attack vector requiring no privileges or user interaction, making it readily exploitable. The attack has a low complexity rating and broadly impacts the confidentiality and integrity of affected systems across security boundaries. An attacker can compromise admin sessions on the Referrals Overview and Social Media analytics pages, potentially leading to unauthorized actions or data theft performed under administrator privileges. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild, as indicated by the vulnerability's absence from the Known Exploited Vulnerabilities (KEV) catalog and its inactive status on threat tracking lists. The EPSS score of 0.00032 reflects minimal community attention relative to other disclosed vulnerabilities. However, the straightforward nature of the vulnerability and the large installed base of WordPress plugins warrant prompt patching by affected organizations.

Impacted Technologies

VendorProductVersion(s)CPE
VeronalabsWP Statistics – Simple, Privacy-Friendly Google Analytics Alternative
>= 0, <= 14.16.4CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.48%
Probability of exploitation in next 30 days
EPSS Percentile
38.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0048 is in the 17th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

plugins.trac.wordpress.org / browser/wp-statistics/tags/14.16.4/assets/dev/javascript/chart.js
plugins.trac.wordpress.org / browser/wp-statistics/tags/14.16.4/src/Service/Analytics/Referrals/ReferralsParser.php
plugins.trac.wordpress.org / browser/wp-statistics/trunk/assets/dev/javascript/chart.js
plugins.trac.wordpress.org / browser/wp-statistics/trunk/src/Service/Analytics/Referrals/ReferralsParser.php
plugins.trac.wordpress.org / changeset
wordfence.com / threat-intel/vulnerabilities/id/9b350b48-05ba-4054-895f-36d7ad71459d