SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14845

MEDIUM · CVSS 6.1 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The NewStatPress WordPress plugin prior to version 1.4.5 is vulnerable due to insufficient sanitization and escaping of data from unauthenticated visitor requests, potentially enabling Stored Cross-Site Scripting (XSS) attacks. This vulnerability allows attackers to inject malicious scripts that execute when users interact with the affected widget, compromising user security. WordPress site administrators using this plugin should prioritize updating to version 1.4.5 or later to mitigate the risk.

CVE
CVE-2026-14845
Severity
MEDIUM
CVSS
6.1
EPSS
0.16%
WordPress

Original NVD Description

The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and later outputting it in one of its widgets, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against users viewing the affected widget.