CVE-2025-47499: WordPress Simple Blog Stats plugin <= 20250416 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Blog Stats allows Stored XSS. This issue affects Simple Blog Stats: from n/a through 20250416.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jeff Starr Simple Blog Stats simple-blog-stats allows Stored XSS.This issue affects Simple Blog Stats: from n/a through <= 20250416.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47499?
CVE-2025-47499 is classified as a stored Cross-site Scripting (XSS) vulnerability, which can allow attackers to execute arbitrary JavaScript code in the context of a user's browser.
How do I fix CVE-2025-47499?
To fix CVE-2025-47499, update the Simple Blog Stats plugin to version 20250417 or later, which contains the necessary patches.
Who is affected by CVE-2025-47499?
CVE-2025-47499 affects users of the Simple Blog Stats plugin in WordPress, specifically versions up to and including 20250416.
What types of attacks can CVE-2025-47499 enable?
CVE-2025-47499 can enable attackers to execute scripts that steal cookies, session tokens, or personal information from users of affected websites.
Is CVE-2025-47499 a local or remote vulnerability?
CVE-2025-47499 is a remote vulnerability, allowing attackers to exploit it without requiring physical access to the vulnerable system.