CVE-2026-66426

WordPress WP-Stats plugin <= 2.56 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WP-Stats <= 2.56 versions.


We have discovered 259 live websites that are affected by CVE-2026-66426.

Run a Free Instant Scan




Affected Software

Product  Wp Stats
Category Wordpress Plugins
Vulnerable Domains259 live websites (100% of Wp Stats install base)
Vulnerable Versions
  • from 0 through 2.56
Vulnerable Versions Count1 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Aug 13, 2026
  • Updated - Aug 13, 2026

Credits

  • testoun | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-66426
United States88 websites



Germany36 websites
Italy23 websites
France18 websites
GB12 websites
Russia9 websites
Poland9 websites
China8 websites
Spain7 websites
Australia4 websites

Website Distribution by TLD

Number of websites using CVE-2026-66426
.com122 websites
.org18 websites
.de16 websites
.it15 websites
.net13 websites
.fr12 websites
.ru6 websites
.co.uk5 websites
.pl5 websites
.info4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-66426

Top websites that are affected by CVE-2026-66426. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.**********.net United States***,***
******.net United States***,***
******.com China***,***
***************.com United States***,***
***********.com United States***,***
************.com United States***,***
*******.***.ni Nicaragua***,***
***************.it Italy*,***,***
***********.com United States*,***,***
***********.com Germany*,***,***
See full domain list

FAQ

CVE-2026-66426 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Wp Stats
A total of 259 websites have been identified as vulnerable to CVE-2026-66426, based on global website indexing conducted by WebTechSurvey.
The Wp Stats is affected by the CVE-2026-66426 vulnerability.
Wp Stats versions up to and including 2.56 are vulnerable to CVE-2026-66426.