Stored Cross-Site Scripting Vulnerability in WP Visitor Statistics Plugin for WordPress
CVE-2026-4303

6.4MEDIUM

What is CVE-2026-4303?

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress has a vulnerability that allows authenticated attackers with contributor-level access to inject arbitrary web scripts into webpages via the 'wsm_showDayStatsGraph' shortcode. This occurs because of insufficient input sanitization and output escaping on user-supplied attributes. As a result, whenever users access an infected page, these scripts can execute, posing a significant risk to website security.

Affected Version(s)

WP Visitor Statistics (Real Time Traffic) 0 <= 8.4

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.