๐Ÿ” CVE Alert

CVE-2025-9116

MEDIUM 5.8

WPS Visitor Counter Plugin <= 1.4.8 - Reflected XSS via $_SERVER['REQUEST_URI']

CVSS Score
5.8
EPSS Score
0.0%
EPSS Percentile
14th

The WPS Visitor Counter WordPress plugin through 1.4.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.

Vendor unknown
Product wps visitor counter
Published Dec 13, 2025
Last Updated Apr 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wps visitor counter

Be the first to know when new medium vulnerabilities affecting unknown wps visitor counter are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WPS Visitor Counter
0 โ‰ค 1.4.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/fe2eb926-96e8-419e-bf41-5531546e6590/

Credits

Bob Matyas WPScan