WordPress plugin WP Statistics has patched a cross-site scripting (XSS) vulnerability that could allow for full website takeover. The vulnerability stems from the plugin failing to sanitize or validate users IP address when it uses a header to identify their IP address. The plugin is made by VeronaLabs and has more than 500,000 active installations. A patch has been issued in version 12.6.7 that addresses the flaw. Researchers urged plugin users to update to the patched version.
Source: https://threatpost.com/wordpress-plugin-wp-statistics-patches-xss-flaw/146248/

