Stored XSS Vulnerability in WP Visitor Statistics Plugin by Osama.esh
CVE-2025-49400

6.5MEDIUM

What is CVE-2025-49400?

A vulnerability exists in the WP Visitor Statistics (Real Time Traffic) plugin by Osama.esh, where improper input validation during web page generation allows for stored cross-site scripting (XSS) attacks. This security flaw can enable attackers to inject malicious scripts, potentially compromising user data and leading to unauthorized actions within affected websites. The vulnerability impacts all versions up to 8.2, necessitating prompt attention and mitigation measures.

Affected Version(s)

WP Visitor Statistics (Real Time Traffic) <= 8.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Thaleikis (Patchstack Alliance)
.