Impact
The vulnerability is a stored cross‑site scripting flaw in the WP Visitor Statistics (Real Time Traffic) plugin that allows an attacker to place malicious JavaScript code into the plugin’s stored data. When a user views pages that display this data, the injected script runs in the user’s browser, potentially compromising the user session or defacing the site. The defect is classified as CWE‑79, improper neutralization of input during web page generation.
Affected Systems
The issue affects the WordPress plugin ‘WP Visitor Statistics (Real Time Traffic)’ provided by the vendor osama.esh. All releases up to, and including, version 7.8 are vulnerable; versions prior to the package’s initial release and newer releases beyond 7.8 are not identified as affected.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity for stored XSS. EPSS is less than 1%, suggesting a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to inject payload via an input channel that the plugin accepts; once stored, the malicious code is served to any visitor of the affected pages.
OpenCVE Enrichment
EUVD