Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows DOM-Based XSS.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 8.3.
Published: 2025-12-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting (XSS)
Action: Apply Patch
AI Analysis

Impact

This vulnerability is an improperly neutralized user input in the WP Visitor Statistics (Real Time Traffic) plugin that allows a DOM‑based Cross‑Site Scripting (XSS) attack. Because the plugin does not encode or filter certain values before inserting them into the page, an attacker can inject malicious scripts that execute in the context of the victim’s browser when the crafted input is processed. The vulnerability description does not specify additional impacts beyond script execution in the browser but discusses the risk inherent in DOM‑based XSS.

Affected Systems

The flaw affects WordPress sites that use the WP Visitor Statistics (Real Time Traffic) plugin version 8.3 or earlier, released by osama.esh. All installations running any version from the earliest release up to and including 8.3 are potentially vulnerable; newer releases are not impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply crafted input that the plugin processes and reflects in the browser without sanitization; this can typically be achieved via a specially crafted URL or form submission. Because the vector is client‑side, any user visiting the affected page will have the injected script executed in their browser.

Generated by OpenCVE AI on April 28, 2026 at 18:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the WP Visitor Statistics (Real Time Traffic) plugin to the latest version (8.4 or newer).
  • If an update is not immediately possible, remove or deactivate the plugin to eliminate the attack surface.
  • Deploy a web application firewall rule or security plugin to block or sanitize suspicious input patterns that target the plugin’s vulnerable parameters.

Generated by OpenCVE AI on April 28, 2026 at 18:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 30 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 17 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Osama.esh
Osama.esh wp Visitor Statistics (real Time Traffic)
Wordpress
Wordpress wordpress
Vendors & Products Osama.esh
Osama.esh wp Visitor Statistics (real Time Traffic)
Wordpress
Wordpress wordpress

Tue, 16 Dec 2025 08:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows DOM-Based XSS.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 8.3.
Title WordPress WP Visitor Statistics (Real Time Traffic) plugin <= 8.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Osama.esh Wp Visitor Statistics (real Time Traffic)
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T19:31:39.107Z

Reserved: 2025-12-15T10:00:33.670Z

Link: CVE-2025-67983

cve-icon Vulnrichment

Updated: 2025-12-17T20:38:17.750Z

cve-icon NVD

Status : Deferred

Published: 2025-12-16T09:16:00.237

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-67983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T18:45:15Z

Weaknesses