Junglewise Threat Intelligence

CVE-2026-4303: osamaesh WP Visitor Statistics Stored XSS in wsm_showDayStatsGraph shortcode

CVE-2026-4303 · Severity: medium · CVSS 6.4 · Published 2026-04-08

Executive brief

The WP Visitor Statistics plugin for WordPress, which provides real-time traffic analytics for website owners, contains a security flaw. This vulnerability allows users with contributor-level access or higher to inject malicious scripts into website pages. When other users or administrators visit these pages, the scripts can execute, potentially leading to unauthorized actions or data theft.

Technical details

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping on user-supplied attributes within the 'wsm_showDayStatsGraph' shortcode. Authenticated attackers with contributor-level permissions or higher can exploit this by injecting arbitrary web scripts into pages. These scripts execute in the context of a user's browser whenever they visit the affected page. The vulnerability exists in all versions up to and including 8.4. A patch has been released in subsequent updates to address the sanitization issues.

Affected products

  • osamaesh WP Visitor Statistics (Real Time Traffic) up to, and including, 8.4

Timeline

  • 2026-04-08: advisory: Initial disclosure by Wordfence and NVD

References