Security Advisory

CVE-2022-4656

5.4
MEDIUM

Vulnerability Description

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.5 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Published Date February 13, 2023
Official Source NIST NVD Advisory