WP Statistics Vulnerability- Unauthenticated Stored Cross-Site Scripting – CVE-2024-2194 |WordPress Plugin Vulnerability Report

Plugin Name: WP Statistics

Key Information:

  • Software Type: Plugin
  • Software Slug: wp-statistics
  • Software Status: Active
  • Software Author: mostafas1990
  • Software Downloads: 22,569,004
  • Active Installs: 600,000
  • Last Updated: March 13, 2024
  • Patched Versions: 14.5.1
  • Affected Versions: <= 14.5

Vulnerability Details:

  • Name: WP Statistics <= 14.5
  • Title: Unauthenticated Stored Cross-Site Scripting
  • Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
  • CVE: CVE-2024-2194
  • CVSS Score: 7.2
  • Publicly Published: March 11, 2024
  • Researcher: Tim Coen
  • Description: The WP Statistics plugin is exposed to a Stored Cross-Site Scripting vulnerability via the URL search parameter in versions up to and including 14.5. The lack of sufficient input sanitization and output escaping enables unauthenticated attackers to execute arbitrary web scripts, potentially compromising site security and user data.


WP Statistics, a popular analytics tool for WordPress, has been identified with a critical vulnerability in versions up to 14.5, threatening the security of websites using the plugin. This vulnerability, classified as Unauthenticated Stored Cross-Site Scripting, allows attackers to execute harmful scripts on a webpage, endangering both website integrity and user privacy. The vulnerability has been addressed in the updated version 14.5.1, ensuring the continued safe use of the plugin.

Detailed Overview:

Identified by security researcher Tim Coen, this vulnerability emphasizes the necessity for strict input validation and output sanitization in web applications, particularly those collecting and displaying data from URLs. The capacity for attackers to inject scripts without authentication amplifies the risk, highlighting the importance of immediate remedial action by website administrators.

Advice for Users:

  • Immediate Action: Update the WP Statistics plugin to version 14.5.1 promptly to mitigate this security vulnerability. This is accessible through the WordPress dashboard under 'Plugins'.
  • Check for Signs of Vulnerability: Monitor for unusual or unauthorized content changes, particularly those involving URL parameters, which may indicate exploitation.
  • Alternate Plugins: Consider exploring alternative analytics plugins that meet security and functionality requirements if necessary.
  • Stay Updated: Regular updates of WordPress components, including plugins, themes, and the core, are crucial for maintaining security and optimal website performance.


The discovery and resolution of CVE-2024-2194 within WP Statistics underscore the ongoing challenges and importance of cybersecurity in the digital realm. For WordPress site administrators, particularly small business owners, understanding the critical role of timely updates and security awareness is essential for protecting digital assets. Vigilance and proactive security practices are fundamental in safeguarding online platforms against evolving threats.


