CVE-2026-14845 PUBLISHED

NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget

Assigner: WPScan
Reserved: 06.07.2026 Published: 31.07.2026 Updated: 31.07.2026

The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in one of its widgets, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against users viewing the affected widget.

Product Status

Vendor Unknown
Product NewStatPress
Versions Default: unaffected
  • affected from 0 to 1.4.5 (excl.)

Credits

  • ApogeeBytes finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE