Impact
The vulnerability is an unauthenticated XSS flaw in the Visitor Traffic Real Time Statistics Pro plugin, allowing an attacker to inject malicious scripts into web pages viewed by other users. This can lead to session hijacking, defacement, or execution of arbitrary client‑side code. The weakness is classified as CWE‑79 and does not require authentication or elevated privileges.
Affected Systems
WordPress sites running the Visitor Traffic Real Time Statistics Pro plugin by CodePress IT Solutions LLC with a version of 11.9.1 or older.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity flaw, yet the EPSS score of less than 1% suggests a low likelihood of real‑world exploitation at present. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that attackers can trigger the XSS by delivering a crafted request to any page that loads the plugin’s output, meaning every anonymous visitor could be exposed.
OpenCVE Enrichment