The plugin fails to properly sanitize some of the data it gathers for statistical purposes. An attacker can use Stored Cross Site Scripting (XSS) and Reflected XSS attack vectors to force a victims browser to perform administrative actions on its behalf. Vulnerability: Stored XSS which executes on the admin panel. The vulnerability is quite a dangerous vulnerability, upgrading your affected websites should be done asap. If an attacker decided to put malicious Javascript code in the affected parameter, it would be saved in the database and printed as-is.”]
Source: https://blog.sucuri.net/2014/11/security-advisory-high-severity-wp-statistics-wordpress-plugin.html