Newstatpress Project maintains a single WordPress plugin that sits within a broadly deployed content-management ecosystem, and its vulnerabilities skew toward serious outcomes with an elevated share reaching critical severity. The exposure centers on input-handling weaknesses endemic to web applications, particularly cross-site scripting and SQL injection flaws that reflect insufficient sanitization of user-supplied data in page generation and database queries. The plugin's attack surface and recurring vulnerability patterns are typical of actively maintained but input-validation-heavy WordPress extensions; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Newstatpress Project over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-4062MEDIUM SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via | May 27, 2015 | 6.5 | 37 | NO | YES |
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web | May 27, 2015 | 3.5 | 28 | NO | YES |
CVE-2022-0206MEDIUM The NewStatPress WordPress plugin before 1.3.6 does not properly escape the whatX parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting is | Feb 14, 2022 | 6.1 | 25 | NO | YES |
CVE-2015-9312MEDIUM The newstatpress plugin before 1.0.5 for WordPress has XSS related to an IMG element. | Aug 14, 2019 | 6.1 | 25 | NO | YES |
CVE-2015-9315CRITICAL The newstatpress plugin before 1.0.1 for WordPress has SQL injection. | Aug 14, 2019 | 9.8 | 24 | NO | NO |
CVE-2015-9313CRITICAL The newstatpress plugin before 1.0.5 for WordPress has SQL injection related to an IMG element. | Aug 14, 2019 | 9.8 | 24 | NO | NO |
CVE-2015-9311MEDIUM The newstatpress plugin before 1.0.6 for WordPress has reflected XSS. | Aug 14, 2019 | 6.1 | 21 | NO | NO |
CVE-2017-20094MEDIUM A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin 1.2.4. This issue affects some unknown processing. The manipulation leads to basic cross | Jun 24, 2022 | 5.4 | 20 | NO | NO |
CVE-2017-18575MEDIUM The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues. | Aug 22, 2019 | 6.1 | 20 | NO | NO |
CVE-2015-9314MEDIUM The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header. | Aug 14, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Newstatpress Project.
Media articles that mention a CVE ID that affects a product developed by Newstatpress Project — matched by CVE ID, not by vendor name.