Impact
The vulnerability allows an unauthenticated attacker to inject arbitrary JavaScript into web pages generated by the plugin. This can occur when the plugin processes user supplied data without proper sanitization. The flaw is a Cross Site Scripting defect (CWE‑79) that could lead to execution of malicious code in the context of the victim’s browser.
Affected Systems
Affected systems are installations of the WordPress Visitor Traffic Real Time Statistics Pro plugin from Codepress, versions 11.10 and lower. The CVE notes that any installation of these older releases is vulnerable; newer releases (11.11 and beyond) incorporate the patch.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity. EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated request to an endpoint that reflects unsanitized input, enabling an attacker to inject and execute script in a visitor’s browser. Consequently, any public WordPress site running an affected version of the plugin could be exposed to cross‑site scripting attacks, potentially affecting confidentiality, integrity, and availability for users of the site.
OpenCVE Enrichment