What is CVE-2026-14845?
CVE-2026-14845 is a Stored XSS vulnerability in the NewStatPress WordPress plugin, caused by a lack of sanitization and escaping of data from unauthenticated visitor requests before output in a widget. This allows unauthenticated attackers to inject malicious scripts targeting users viewing the affected widget. Versions before 1.4.5 are impacted, and updating is required.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What can an attacker exploiting CVE-2026-14845 try to do?
An unauthenticated attacker can inject malicious scripts into the NewStatPress widget to target users viewing the affected widget.
To which version should the NewStatPress plugin be updated to protect against this vulnerability?
The plugin should be updated to version 1.4.5 or higher, as versions before 1.4.5 are impacted.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.