Impact
The vulnerability resides in the StatCounter plugin’s handling of the post author's nickname within a JavaScript context. Because the nickname is inserted directly into a <script> block without proper escaping, an attacker can place malicious script code. This results in stored XSS that executes in the browsers of all users who visit the author’s posts.
Affected Systems
WordPress sites running the StatCounter – Free Real Time Visitor Stats plugin version 2.1.1 or earlier. No other versions are currently listed as affected.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium‑severity flaw; the EPSS score is not available, and the vulnerability is not in CISA’s KEV catalog. The likely attack vector is an authenticated attacker with Author‑level access or higher, who supplies a crafted nickname. Once the nickname is stored, the payload executes automatically for all visitors to the author’s posts.
OpenCVE Enrichment