Impact
Unauthenticated Cross Site Scripting (XSS) is present in Visitor Traffic Real Time Statistics Pro plugin versions 11.21 and earlier, allowing an attacker to inject arbitrary script into pages viewed by site visitors. This can lead to credential theft, defacement, or other client‑side compromises. The weakness is a classic input validation flaw classified as CWE-79.
Affected Systems
The vulnerability affects the WordPress plugin Visitor Traffic Real Time Statistics Pro from CODEPRESS IT Solutions LLC, specifically all releases up to and including version 11.21. It is relevant to any WordPress site that has this plugin installed and active.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting no known large‑scale exploitation yet. Based on the description, the likely attack vector is an unauthenticated user visiting a crafted URL or manipulating query parameters in the statistics page, triggering the injected script.
OpenCVE Enrichment