Impact
The vulnerability is an improper neutralization of input during web page generation, allowing attackers to store malicious scripts in the WordPress WP Visitor Statistics (Real Time Traffic) plugin. Stored XSS can execute arbitrary JavaScript in the browsers of site visitors, enabling session hijacking, credential theft, defacement, or further exploitation of the target application. This weakness is identified as CWE-79, representing a severe impact on the confidentiality, integrity, and availability of user data and website functionality.
Affected Systems
The affected product is the WP Visitor Statistics (Real Time Traffic) WordPress plugin by osama.esh, versions up to and including 8.2. Users who have installed any of these versions on WordPress sites are susceptible; newer releases (8.3 or later) contain the fix.
Risk and Exploitability
The CVSS base score of 9.8 classifies this as critical, yet the EPSS score of less than 1% indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, so no known mass exploitation reports exist. Attackers would likely leverage the plugin’s data entry forms to inject malicious payloads, which are then served to all site visitors, making it a low effort, high impact attack scenario.
OpenCVE Enrichment
EUVD