Junglewise Threat Intelligence

CVE-2022-50945: 3dady Real-Time Web Stats stored XSS in plugin options

CVE-2022-50945 · Severity: medium · CVSS 6.4 · Published 2026-05-10

Executive brief

The 3dady Real-Time Web Stats plugin for WordPress, which is used to track website visitor statistics, contains a security flaw. An attacker with basic login credentials can inject malicious scripts into the plugin's settings. When other users or administrators view the statistics dashboard, these scripts can execute, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the 3dady Real-Time Web Stats plugin version 1.0 for WordPress. The vulnerability is located in the plugin options panel, specifically within the 'dady_input_text' and 'dady2_input_text' fields, which fail to properly sanitize user-supplied input. An authenticated attacker with access to the plugin settings can inject arbitrary JavaScript payloads. These payloads are stored in the database and executed in the context of any user (including administrators) who subsequently visits the affected settings page. This can lead to session hijacking or unauthorized administrative actions.

Affected products

  • 3dady 3dady Real-Time Web Stats 1.0

Timeline

  • 2022-08-24: other: Vulnerability discovered by researcher
  • 2022-09-23: disclosed: Exploit published on Exploit-DB
  • 2026-05-10: advisory: NVD/VulnCheck advisory published

References