Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows Stored XSS.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 7.2.
Published: 2025-01-24
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The description indicates an improper neutralization of user input during web page generation in the WP Visitor Statistics (Real Time Traffic) plugin, allowing Stored XSS. Based on typical XSS behavior, it is inferred that attacker‑supplied content is stored in the plugin’s statistics fields and later rendered on the site. As a result, users who view the affected pages may have malicious scripts executed in their browsers, potentially leading to cookie theft, defacement, or redirects to malicious sites. The description does not explicitly state that direct server‑side code execution is possible; it is inferred that the primary impact is client‑side script execution.

Affected Systems

The vulnerability affects the WordPress plugin WP Visitor Statistics (Real Time Traffic) by osama.esh. All plugin versions from the initial release up to and including 7.2 are impacted.

Risk and Exploitability

The issue has a CVSS score of 6.5, placing it in the medium severity range, and an EPSS score of less than 1 %, indicating a low likelihood of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Based on typical XSS exploitation patterns, it is inferred that attackers would input malicious payloads into the plugin’s statistics fields, which are then stored and later displayed on the site. Because the vulnerability is stored, an attacker can target site visitors without needing direct access to the file system, though exploitation requires that users load the affected content.

Generated by OpenCVE AI on May 2, 2026 at 05:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Immediately update the WP Visitor Statistics (Real Time Traffic) plugin to the latest version that removes the XSS flaw.
  • If an update cannot be applied right away, deactivate or uninstall the plugin until a patched version is available to prevent the stored malicious scripts from being served to visitors.
  • Apply site‑wide input validation or a web application firewall rule that blocks or sanitizes XSS payloads in WordPress statistical data fields.

Generated by OpenCVE AI on May 2, 2026 at 05:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3869 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.2. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows Stored XSS.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 7.2.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 24 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jan 2025 17:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.2.
Title WordPress WP Visitor Statistics (Real Time Traffic) plugin <= 7.2 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:31.731Z

Reserved: 2025-01-23T14:52:05.566Z

Link: CVE-2025-24675

cve-icon Vulnrichment

Updated: 2025-01-24T18:46:01.442Z

cve-icon NVD

Status : Deferred

Published: 2025-01-24T18:15:41.340

Modified: 2026-06-17T08:59:25.267

Link: CVE-2025-24675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T05:30:26Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')