OVERVIEW CVE-2026-5231 is a stored cross-site scripting (XSS) vulnerability in the WP Statistics plugin for WordPress, affecting all versions up to and including 14.16.4. The flaw exists in the plugin's referral parser and chart rendering functionality, where the utm_source parameter is insufficiently sanitized and later inserted into admin page markup without proper output escaping. This allows unauthenticated attackers to inject malicious scripts that execute in administrator sessions. SEVERITY The vulnerability carries a CVSS score of 7.2 (HIGH) with a network-based attack vector requiring no privileges or user interaction, making it readily exploitable. The attack has a low complexity rating and broadly impacts the confidentiality and integrity of affected systems across security boundaries. An attacker can compromise admin sessions on the Referrals Overview and Social Media analytics pages, potentially leading to unauthorized actions or data theft performed under administrator privileges. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild, as indicated by the vulnerability's absence from the Known Exploited Vulnerabilities (KEV) catalog and its inactive status on threat tracking lists. The EPSS score of 0.00032 reflects minimal community attention relative to other disclosed vulnerabilities. However, the straightforward nature of the vulnerability and the large installed base of WordPress plugins warrant prompt patching by affected organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Veronalabs | WP Statistics – Simple, Privacy-Friendly Google Analytics Alternative | >= 0, <= 14.16.4CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.