← Back
Web Application
CVE-2026-19794 high CVSS 7.2

The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...

Summary

The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up...

AI summary openai / gpt-4o

WordPressプラグインのWP-Statsには、バージョン2.56までのすべてのバージョンにおいてストアドXSSの脆弱性があります。この脆弱性は入力サニタイズと出力エスケープが不十分であるため、認証されていない攻撃者が任意のスクリプトを注入でき、ユーザーが該当ページをアクセスする際にスクリプトが実行されます。
❓ What is the problem
WordPressのWP-StatsプラグインにおけるストアドXSSの脆弱性
📍 Affected scope
WP-Statsプラグイン バージョン2.56以下
🔥 Severity
任意のウェブスクリプトを注入可能で、ユーザーがページを訪問時にスクリプトが実行される可能性がある。
🔧 How to fix
WP-Statsの新しいバージョンにアップデートし、入力サニタイズと出力エスケープを強化する。
🛡️ Workaround
プラグインを無効化して使用を控える。
🔍 Detection
脆弱なバージョンのプラグインがインストールされているかを確認する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →