Stored XSS Vulnerability in WP Visitor Statistics Plugin by Osama.esh
CVE-2025-49400
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2025
What is CVE-2025-49400?
A vulnerability exists in the WP Visitor Statistics (Real Time Traffic) plugin by Osama.esh, where improper input validation during web page generation allows for stored cross-site scripting (XSS) attacks. This security flaw can enable attackers to inject malicious scripts, potentially compromising user data and leading to unauthorized actions within affected websites. The vulnerability impacts all versions up to 8.2, necessitating prompt attention and mitigation measures.
Affected Version(s)
WP Visitor Statistics (Real Time Traffic) <= 8.2