WordPress Plugin Vulnerabilities

NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget

Description

The plugin does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in one of its widgets, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against users viewing the affected widget.

Proof of Concept

Affects Plugins

Fixed in 1.4.5

References

Classification

Type
XSS
CWE

Miscellaneous

Original Researcher
ApogeeBytes
Submitter
ApogeeBytes
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 18 days ago)
Added
2026-07-13 (about 17 days ago)
Last Updated
2026-07-13 (about 17 days ago)

Other