
CVE-2026-4303 The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wsm_showDayStatsGraph' shortcode in al… https://www.cve.org/CVERecord?id=CVE-2026-4303
Post summary
CVE-2026-4303 exposes a stored XSS flaw in the WP Visitor Statistics plugin’s shortcode, with no evidence of exploitation or mitigation provided.
