Impact
The Visitor Stats Widget plugin does not properly neutralise user supplied data when rendering web pages, creating a reflected cross‑site scripting flaw. An attacker could embed malicious script in a URL or form field that the plugin echoes back to a victim’s browser. The injected code runs within the victim’s browser session and could perform arbitrary actions, depending on the privileges the victim holds. This vulnerability is identified as CWE‑79.
Affected Systems
All WordPress sites that have installed Shahjada’s Visitor Stats Widget plugin from the first released version through version 1.5.0 are affected. Sites upgraded to 1.6.0 or later are not impacted. Any user visiting a page that includes the plugin’s unescaped output could be exposed to an attacker who can insert malicious input via the plugin’s public interface.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity for an attacker who can trigger this flaw. The EPSS of less than 1% signals a low probability of exploitation at the time of this analysis, and the incident is not listed in CISA’s KEV catalog. The likely attack vector is reflected input in URLs or form submissions that are subsequently rendered back to the victim’s browser. Execution is confined to the victim’s browser context and does not allow broader system compromise.
OpenCVE Enrichment