CVE-2026-15780Disclosure

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' parameter in all versions up to, and including, 14.16.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload can be planted without authentication via the public /wp-statistics/v2/hit REST endpoint, because the required signature is exposed on the public homepage and a base64-encoded page_uri POST parameter overrides the previously sanitized REQUEST_URI, allowing the malicious utm_campaign value to bypass sanitization and be stored in the database.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-08-19: 4PoC Mentioned / Linked · 2026-08-19: 1Patch / Workaround · 2026-08-19: 1Technical Details · 2026-08-19: 408-19
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets5 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-15780 The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' par… https://www.cve.org/CVERecord?id=CVE-2026-15780

    Post summary

    WP Statistics WordPress plugin CVE‑2026‑15780 is a stored XSS vulnerability triggered via the 'utm_campaign' parameter; no PoC, exploit, patch, or active exploitation details are disclosed.

    01010746
    58.0K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-15780 - Stored XSS in WP Statistics plugin ≤14.16.8 via utm_campaign param. Unauthenticated payload injection. CVSS 7.2. Unpatched - update/disable now. #CVE #WordPress #infosec https://www.valtersit.com/cve/CVE-2026-15780/ #CVE #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico #switczerland #iceland #israel

    Post summary

    The post discloses a stored XSS vulnerability in WP Statistics plugin (CVE‑2026‑15780), provides technical details and a CVSS score, and urges users to update or disable the plugin.

    0001055
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-15780 The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_campaign' par… https://www.cve.org/CVERecord?id=CVE-2026-15780 ----- Traducción: CVE-2026-15780 El … https://infoflow.cloud`

    Post summary

    The brief tweet announces CVE-2026-15780 as a stored XSS flaw in the WP Statistics WordPress plugin and links to the official CVE record, but provides no proof of concept, exploit code, patch, or evidence of active exploitation.

    0001063
    100 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-15780 Stored XSS in WP Statistics Plugin via utm_campaign Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-15780 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The text announces a Stored XSS vulnerability (CVE‑2026‑15780) in the WP Statistics Plugin that can be triggered via the utm_campaign parameter, providing a link to details but lacking PoC, exploit, patch, or active exploitation evidence.

    00000101
    4.1K followersView on X

Explore more