Statify – Extended Evaluation
Statify – Extended Evaluation has one disclosed vulnerability in the WordSec catalog, all reported in 2023; it is fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 5.5 out of 10.
The most common weakness is Improper Neutralization Of Formula Elements In A CSV File, behind 1 of the records (100%).
The one issue recorded for Statify – Extended Evaluation has a vendor fix available, so running the current release closes it.
Statify – Extended Evaluation is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
Statify – Extended Evaluation <= 2.6.3 - Authenticated (Admin+) CSV Injection
Read the full analysisVulnerability Records

Statify – Extended Evaluation
Author
Patrick Robrecht
The functionality of this extension became part of Statify. You can update to Statify 2.x and uninstall this plugin. This plugin evaluates the data collected with the privacy-friendly Statify Plugin which is only saving date, referrer and target url for every page view. The plugin creates evaluations for the following criteria: views per year / month / day most popular content views per post views per referrer The results are shown in data tables and diagrams. The evaluation results can be downloaded as CSV files (for an import into LibreOffice Calc or Microsoft Excel).
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C