Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28300 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 8.2. |
Solution
Update the WordPress WP Visitor Statistics (Real Time Traffic) plugin to the latest available version (at least 8.3).
Workaround
No workaround given by the vendor.
Tue, 28 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-502 | |
| References |
|
Tue, 28 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of Untrusted Data vulnerability in osama.esh PressApps Knowledge Base Contextual Sidebar Addon pressapps-knowledge-base allows Object Injection.This issue affects PressApps Knowledge Base Contextual Sidebar Addon: from n/a through <= 4.2.1. | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 8.2. |
| Title | WordPress PressApps Knowledge Base Contextual Sidebar Addon Plugin <= 4.2.1 - PHP Object Injection Vulnerability | WordPress WP Visitor Statistics (Real Time Traffic) Plugin <= 8.2 - Cross Site Scripting (XSS) Vulnerability |
| Weaknesses | CWE-79 | |
| References |
|
Thu, 23 Apr 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| References |
|
Thu, 23 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 8.2. | Deserialization of Untrusted Data vulnerability in osama.esh PressApps Knowledge Base Contextual Sidebar Addon pressapps-knowledge-base allows Object Injection.This issue affects PressApps Knowledge Base Contextual Sidebar Addon: from n/a through <= 4.2.1. |
| Title | WordPress WP Visitor Statistics (Real Time Traffic) Plugin <= 8.2 - Cross Site Scripting (XSS) Vulnerability | WordPress PressApps Knowledge Base Contextual Sidebar Addon Plugin <= 4.2.1 - PHP Object Injection Vulnerability |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Wed, 20 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 20 Aug 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 8.2. | |
| Title | WordPress WP Visitor Statistics (Real Time Traffic) Plugin <= 8.2 - Cross Site Scripting (XSS) Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-04-28T16:13:03.174Z
Reserved: 2025-06-04T15:44:03.662Z
Link: CVE-2025-49400
Updated: 2025-08-20T18:06:38.640Z
Status : Deferred
Published: 2025-08-20T08:15:35.540
Modified: 2026-04-28T19:33:04.827
Link: CVE-2025-49400
No data.
OpenCVE Enrichment
Updated: 2026-04-30T08:15:32Z
EUVD