
CVE-2026-19794 The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input sanitization and o… https://www.cve.org/CVERecord?id=CVE-2026-19794
Post summary
The WP‑Stats plugin for WordPress is vulnerable to stored cross‑site scripting in all versions up to 2.56 due to insufficient input sanitization.
