Impact
The vulnerability allows an unauthenticated attacker to inject malicious JavaScript into web pages that use the Visitors Traffic Real Time Statistics plugin. The bad input does not appear to be validated or escaped, enabling the execution of attacker‑supplied code in the context of the site visitor. This can lead to session hijacking, credential theft, defacement or the execution of further client‑side attacks against users visiting the affected pages.
Affected Systems
Vulnerable versions of the WordPress Visitors Traffic Real Time Statistics plugin, as distributed by wp-buy, are affected when the installed version is 8.11 or earlier. Any WordPress site that has made the plugin available to visitors who can submit data or view statistics is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk impact level. The EPSS score is not available, so the current probability of exploitation is unknown, but the lack of authentication requirements means the attacker does not need privileged access. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. The most likely attack vector is the plugin’s public interfaces that accept input without proper sanitization, which can be abused by anyone who can send requests to the site.
OpenCVE Enrichment