Statify Widget
Statify Widget has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.4, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Statify Widget has a vendor fix available, so running the current release closes it.
All of these findings were reported by theviper17y. Statify Widget is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2025-48322Statify Widget <= 1.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Statify Widget
Author
Finn Dohrn
The Statify Widget shows the most popular content from the Statify plugin, which collects statistics in compliance with data protection regulations. Fast and clear! What is Statify? Statify is a plugin for visitor statistics with emphasis on privacy, transparency and clarity. Note: This widget only works with the main plugin Statify. Features Popular Posts: Sum up all view from Statify and put it together in a widget Shortcodes: The counter for each post/page can be put everywhere Custom Post Types: Statify Widget supports custom post types, that can be displayed Intelligent summary: Once there are different paths to a content, the widget adds them together Period Selectable: It is possible to choose an individual daily period for the post popular content Custom Widget Template: You can add individual post/page paramater to widget template (see FAQ) New: Customize cache time: Change default 4 minutes cache time to another value! (see FAQ) Shortcode The shortcode [statify-count] can be used to display calls to the current post or page. With the options “prefix” and “suffix” displayed texts can be checked before (prefix) and after (suffix) the calls: [statify-count prefix="Total " suffix=" calls." days="8"] Parameter: prefix Sentence before views suffix Sentence after views days Inteval for view statistics Result: A total of 243 views. Widget Settings The following settings can be made in the widget: Title Content Type (Default: post ) Category (when content type post is select) Amount of entries (default: 5) Show views (default: No) Custom text (Replace variable for views: %VIEWS%) Number of past days (0 days = all statistics) Support Friendly questions about the widget I like to answer under Support. If you like my work and want to support me, feel free to rate this plugin! Author Finn Dohrn Homepage
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C