CVE-2026-5231Active Exploitation

MEDIUMCVSS 7.2 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and including, 14.16.4. This is due to insufficient input sanitization and output escaping. The plugin's referral parser copies the raw utm_source value into the source_name field when a wildcard channel domain matches, and the chart renderer later inserts this value into legend markup via innerHTML without escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in admin pages that will execute whenever an administrator accesses the Referrals Overview or Social Media analytics pages.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days

What's happening

  • Active exploitation reported across 4 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 6 mentions (2026-04-17); latest day: 1
  • 8 total mentions across 3 days

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-04-17: 6Mentions · 2026-04-21: 1Mentions · 2026-04-22: 1PoC Mentioned / Linked · 2026-04-17: 2Active Exploitation · 2026-04-17: 2Active Exploitation · 2026-04-21: 1Active Exploitation · 2026-04-22: 1Patch / Workaround · 2026-04-17: 2Technical Details · 2026-04-17: 5Technical Details · 2026-04-21: 1Technical Details · 2026-04-22: 104-1704-2104-22
Signal classification3 categories
Active Exploitation
450.0%
Disclosure
337.5%
PoC
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-04-176
Active Exploitation2Disclosure3PoC1
2026-04-211
Active Exploitation1
2026-04-221
Active Exploitation1
Full discourse8 posts
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    ⚠️ CISA KEV — CVE-2026-5231 The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in al... CVSS 7.2 · Actively exploited in the wild 🔗 http://ctiwatch.cloud/vulnerabilities/CVE-2026-5231 #CISA #KEV #Vulnerability #CyberSecurity

    Post summary

    CISA notes CVE-2026-5231 is a stored XSS in the WP Statistics plugin with a CVSS score of 7.2, actively exploited in the wild. No patch or workaround information is provided in the snippet.

    00000103
    5.6K followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2026-5231 Exploit in the wild confirmed for CVE-2026-5231 (CVSS 7.2). The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    Active exploitation of CVE-2026-5231 in WP Statistics plugin has been confirmed with a CVSS score of 7.2, but no PoC or patch is provided.

    00000136
    5.6K followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-5231-wp-statistics-version-14-16-4-high-vulnerability-proof-of-concept CVE-2026-5231 #WordPress plugin #vulnerability wp-statistics #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    A proof‑of‑concept for CVE‑2026‑5231 against WP‑Statistics 14‑16‑4 has been posted and linked in the tweet, but the post lacks detailed technical or exploit code descriptions.

    0000043
    7 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    WP Statistics plugin CVE-2026-5231 is actively exploited — hackers can inject scripts via 'utm_source', affecting countless WordPress sites. Patch now to prevent unauthorized access. #NerdieNews #CyberSecurity #InfoSec #Vulnerability #ICS #WordPress https://t.co/PB9OM3tFAh

    Post summary

    CVE-2026-5231, a vulnerability in the WP Statistics plugin, is being actively exploited by attackers who inject malicious scripts through the 'utm_source' parameter, and a patch is available to mitigate the risk.

    0000042
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5231 The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in all versions up to, and including, 14.16.4. This i… https://www.cve.org/CVERecord?id=CVE-2026-5231

    Post summary

    The WP Statistics plugin for WordPress is vulnerable to a stored XSS attack through the 'utm_source' parameter, affecting all versions up to 14.16.4.

    0000066
    57.2K followersView on X
  • CypherByte@cypherbyteio
    Active Exploitation

    Your marketing links are being weaponized. 🔗🏴‍☠️ A critical Stored XSS vulnerability (CVE-2026-5231) in WP Statistics allows attackers to inject malicious code via simple utm_source tags. No login required. The moment an admin checks the stats, the script triggers. Full dashboard takeover. If you're running this plugin, patch immediately. The next exploit is already in the wild. 🛡️ Stay ahead: https://www.cypherbyte.io/blog/cve-2026-5231-wp-statistics-stored-xss-utm-source/ #WordPress #XSS #CyberSecurity #WPStatistics

    Post summary

    Critical WP Statistics Stored XSS (CVE‑2026‑5231) is being actively exploited via utm_source tags; patching is urgently required.

    0000047
    6 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-5231 The WP Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'utm_source' parameter in a… CVSS 7.2 Full analysis → https://sec.kaitan.id/cves/CVE-2026-5231 #WordPress #CyberSecurity #InfoSec

    Post summary

    The post announces CVE-2026-5231, a high‑severity Stored XSS vulnerability in the WP Statistics plugin, providing basic technical details but no exploits or patches.

    000001
    145 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5231 Stored Cross-Site Scripting in WP Statistics Plugin Versions Up to 14.16.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5231

    Post summary

    CVE-2026-5231 alerts to a stored XSS flaw in WP Statistics plugin versions up to 14.16.4, providing technical details but no PoC, exploit code, or evidence of active exploitation.

    0000043
    4.0K followersView on X

Explore more