Unrated severityNVD Advisory· Published Feb 13, 2023· Updated Mar 20, 2025
WP Visitor Statistics (Real Time Traffic) < 6.5 - Contributor+ Stored XSS via Shortcode
CVE-2022-4656
Description
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.5 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <6.5
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/05976ed8-5a26-4eae-adb2-0ea3b2722391mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.