← back
CVE-2021-24350CWE-79

Visitors <= 0.3 - Unauthenticated Stored Cross-Site Scripting (XSS)

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.3%
exploitation probability
1.3%top 32% of all CVEs
observed exploitation
nono source reports it
The Visitors WordPress plugin through 0.3 is affected by an Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. The plugin would display the user's user agent string without validation or encoding within the WordPress admin panel.
Affected products
Unknown · Visitors