What is CVE-2026-19794?
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the WP-Stats plugin for WordPress, affecting all versions up to and including 2.56. This allows unauthenticated attackers to inject arbitrary web scripts into pages. Users should update the plugin immediately or disable it.
Azərbaycanca: WordPress-in WP-Stats plaginində (2.56 daxil olmaqla bütün versiyalarda) Stored Cross-Site Scripting (XSS) zəifliyi aşkar edilib. Bu, autentifikasiya olunmamış hücumçulara xüsusi səhifələrə zərərli skriptlər yerləşdirməyə imkan verir. Plagin dərhal ən son versiyaya yenilənməli və ya müvəqqəti olaraq deaktiv edilməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the WP-Stats plugin are affected by CVE-2026-19794?
All versions up to and including 2.56 are affected by this Stored XSS vulnerability.
Is authentication required for an attacker to exploit CVE-2026-19794?
No, this vulnerability can be exploited by unauthenticated attackers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.