CVE-2022-4656 describes a Stored Cross-Site Scripting (XSS) vulnerability in the WP Visitor Statistics (Real Time Traffic) WordPress plugin versions prior to 6.5, stemming from insufficient validation and escaping of a shortcode attribute. This flaw allows users with a role as low as contributor to perform Stored XSS attacks. Rated Medium with a CVSS score of 5.4, the vulnerability has a network attack vector and low complexity, requiring user interaction and low privileges (contributor role) to achieve low impacts on confidentiality and integrity. There is currently no evidence of active exploitation, nor are public exploit codes available in common repositories like Metasploit or ExploitDB. Furthermore, the vulnerability has received no community discussion or media coverage, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.5CPE matchmatch criteria | cpe:2.3:a:codepress:visitor_statistics:*:*:*:*:-:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.