Impact
The WP Visitor Statistics (Real Time Traffic) plugin contains a broken access control flaw classified as CWE-862. This error allows a user to reach functionality that is not properly constrained by ACLs, potentially exposing or modifying sensitive visitor statistics data. The impact is primarily confidentiality and integrity: an attacker could view or alter statistics that are intended only for administrators.
Affected Systems
The flaw affects the WordPress plugin developed by osama.esh, WP Visitor Statistics (Real Time Traffic), for all releases up to and including version 8.4. Any installation of the plugin in that version range is vulnerable, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation under current conditions. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remotely via HTTP requests to plugin endpoints; as the flaw concerns missing authorization, an attacker with any website access could target the vulnerable functions.
OpenCVE Enrichment
EUVD