Extension WordPress
Vulnérabilités StatCounter – Free Real Time Visitor Stats
Cette page rassemble les failles publiées pour StatCounter – Free Real Time Visitor Stats, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de StatCounter – Free Real Time Visitor Stats
4 fiches
StatCounter – Free Real Time Visitor Stats <= 2.1.1 – Authenticated (Contributor+) Stored Cross-Site Scripting
The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.1.1
2.1.2
26/06/2026
StatCounter <= 2.1.1 – Authenticated (Author+) Stored Cross-Site Scripting via Author Nickname
The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.1.1 This is due to insufficient output escaping on the post author's nickname in the…
*-2.1.1
2.1.2
28/05/2026
Official StatCounter Plugin <= 2.1.0 – Authenticated (Contributor+) Stored Cross-Site Scripting via Nickname
The StatCounter – Free Real Time Visitor Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user's Nickname in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This…
*-2.1.0
2.1.1
18/02/2026
StatCounter <= 2.0.6 – Admin+ Stored Cross-Site Scripting
The StatCounter WordPress plugin before 2.0.7 does not sanitise and escape the Project ID and Secure Code settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
[*, 2.0.7)
2.0.7
26/01/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.