{"api_version":"1","generated_at":"2026-07-23T21:16:30+00:00","cve":"CVE-2021-25042","urls":{"html":"https://cve.report/CVE-2021-25042","api":"https://cve.report/api/cve/CVE-2021-25042.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-25042","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-25042"},"summary":{"title":"CVE-2021-25042","description":"The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude. Furthermore, due to the lack of validation, sanitisation and escaping, users could set a malicious value and perform Cross-Site Scripting attacks against logged in admin","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2022-02-28 09:15:00","updated_at":"2022-03-08 16:56:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/05b9e478-2d3b-4460-88c1-7f81d3a68ac4","name":"https://wpscan.com/vulnerability/05b9e478-2d3b-4460-88c1-7f81d3a68ac4","refsource":"MISC","tags":[],"title":"Attention Required! | Cloudflare","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-25042","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-25042","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Krzysztof Zając","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"25042","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"plugins-market","cpe5":"wp_visitor_statistics_\\(real_time_traffic\\)","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ID":"CVE-2021-25042","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC","TITLE":"WP Visitor Statistics (Real Time Traffic) < 5.5 - Arbitrary IP Address Exclusion to Stored XSS"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","generator":"WPScan CVE Generator","affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"WP Visitor Statistics (Real Time Traffic)","version":{"version_data":[{"version_affected":"<","version_name":"5.5","version_value":"5.5"}]}}]}}]}},"description":{"description_data":[{"lang":"eng","value":"The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude. Furthermore, due to the lack of validation, sanitisation and escaping, users could set a malicious value and perform Cross-Site Scripting attacks against logged in admin"}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://wpscan.com/vulnerability/05b9e478-2d3b-4460-88c1-7f81d3a68ac4","name":"https://wpscan.com/vulnerability/05b9e478-2d3b-4460-88c1-7f81d3a68ac4"}]},"problemtype":{"problemtype_data":[{"description":[{"value":"CWE-862 Missing Authorization","lang":"eng"}]}]},"credit":[{"lang":"eng","value":"Krzysztof Zając"}],"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-02-28 09:15:00","lastModifiedDate":"2022-03-08 16:56:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:plugins-market:wp_visitor_statistics_\\(real_time_traffic\\):*:*:*:*:*:wordpress:*:*","versionEndExcluding":"5.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"25042","Ordinal":"199804","Title":"CVE-2021-25042","CVE":"CVE-2021-25042","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"25042","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}