HIGH

CVE-2026-17506

Independent Analytics <= 2.15.0 - Unauthenticated Stored Cross-Site Scripting

CVSS v3

7.2

HIGH

EPSS Score

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions up to, and including, 2.15.0. This is due to the get_cell_content() function applying urldecode() after esc_url() when rendering the URL column for 404 entries — a sequence that allows percent-encoded HTML to pass URL validation and then be reconstructed as raw markup, which wp_kses_post() does not strip because it retains img elements and data-* at

Technical details

CVSS v3 Vector
3.1
Published
8/5/2026
Last Modified
8/5/2026

Frequently asked questions

What is CVE-2026-17506?

The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions up to, and including, 2.15.0. This is due to the get_cell_content() function applying urldecode() after esc_url() when rendering the URL column for 404 entries — a sequence that allows percent-encoded HTML to pass URL validation and then be reconstructed as raw markup, which wp_kses_post() does not strip because it retains img elements and data-* at

Is CVE-2026-17506 actively exploited?

Active exploitation of CVE-2026-17506 has not been confirmed. The EPSS score is N/A%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-17506?

CVE-2026-17506 has a CVSS v3 base score of 7.2 (HIGH severity), with vector string 3.1.

Is CVE-2026-17506 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.