Visitors Traffic Real Time Statistics <= 8.11 - Unauthenticated Stored Cross-Site Scripting
high
The Visitors Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute w...
- CVSS:
- 7.2
- Affected:
- up to 8.11
- Fixed in:
- 8.12
- Disclosed:
- Aug 13, 2026
CVE-2026-28175 on NVD →
Visitor Traffic Real Time Statistics <= 8.4 - Unauthenticated Stored Cross-Site Scripting
high
The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scr...
- CVSS:
- 7.2
- Affected:
- up to 8.4
- Fixed in:
- 8.5
- Disclosed:
- Apr 3, 2026
CVE-2026-2936 on NVD →
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] <= 7.2
unknown
[en] Missing Authorization vulnerability in wp-buy Visitors Traffic Real Time Statistics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Visitors Traffic Real Time Statistics: from n/a through 7.2.
- Affected:
- up to 7.2
- Fixed in:
- 7.2
- Disclosed:
- Jan 2, 2025
CVE-2023-47557 on NVD →
Visitors Traffic Real Time Statistics <= 7.2 - Missing Authorization via multiple AJAX actions
medium
The Visitors Traffic Real Time Statistics plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 7.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to view visitor stat...
- CVSS:
- 4.3
- Affected:
- up to 7.2
- Fixed in:
- 7.3
- Disclosed:
- Nov 7, 2023
CVE-2023-47557 on NVD →
Visitor Traffic Real Time Statistics <= 6.7 - Missing Authorization to Information Disclosure
medium
The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.7. This makes it possible for authenticated attackers to retrieve site statistics.
- CVSS:
- 4.3
- Affected:
- up to 6.8
- Fixed in:
- 6.9
- Disclosed:
- Jun 5, 2023
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 6.9
unknown
The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 6.7. This makes it possible for authenticated attackers to retrieve site statistics.
- Affected:
- up to 6.9
- Fixed in:
- 6.9
- Disclosed:
- Jun 5, 2023
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 3.9
unknown
[en] The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue
- Affected:
- up to 3.9
- Fixed in:
- 3.9
- Disclosed:
- Nov 8, 2021
CVE-2021-24829 on NVD →
Visitor Traffic Real Time Statistics <= 3.8 - Subscriber+ SQL Injection
high
The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue
- CVSS:
- 8.8
- Affected:
- up to 3.8
- Fixed in:
- 3.9
- Disclosed:
- Oct 6, 2021
CVE-2021-24829 on NVD →
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 2.12
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attac...
- Affected:
- up to 2.12
- Fixed in:
- 2.12
- Disclosed:
- May 14, 2021
CVE-2021-24193 on NVD →
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 2.12
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable p...
- Affected:
- up to 2.12
- Fixed in:
- 2.12
- Disclosed:
- May 14, 2021
CVE-2021-24192 on NVD →
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 2.12
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer (User Switching) WordPress plugin before 1.8, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...
- Affected:
- up to 2.12
- Fixed in:
- 2.12
- Disclosed:
- May 14, 2021
CVE-2021-24195 on NVD →
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 2.12
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit Failed Login Attempts WordPress plugin before 2.9, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which he...
- Affected:
- up to 2.12
- Fixed in:
- 2.12
- Disclosed:
- May 14, 2021
CVE-2021-24194 on NVD →
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 2.12
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection & No Right Click WordPress plugin before 3.1.5, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which hel...
- Affected:
- up to 2.12
- Fixed in:
- 2.12
- Disclosed:
- May 14, 2021
CVE-2021-24188 on NVD →
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 2.12
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptcha for admin login page WordPress plugin before 2.4, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which...
- Affected:
- up to 2.12
- Fixed in:
- 2.12
- Disclosed:
- May 14, 2021
CVE-2021-24189 on NVD →
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 2.12
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Marketing Mailer WordPress plugin before 1.5.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps...
- Affected:
- up to 2.12
- Fixed in:
- 2.12
- Disclosed:
- May 14, 2021
CVE-2021-24190 on NVD →
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 2.12
unknown
[en] Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site Under Construction WordPress plugin before 1.8.2, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which h...
- Affected:
- up to 2.12
- Fixed in:
- 2.12
- Disclosed:
- May 14, 2021
CVE-2021-24191 on NVD →
Visitor Traffic Real Time Statistics <= 2.11 - Missing Authorization to Arbitrary Plugin Installation/Activation
high
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers...
- CVSS:
- 8.8
- Affected:
- up to 2.11
- Fixed in:
- 2.12
- Disclosed:
- Apr 22, 2021
CVE-2021-24193 on NVD →
Visitor Traffic Real Time Statistics <= 2.13 - Cross-Site Request Forgery to Arbitrary Plugin Installation/Activation
high
The Visitor Traffic Real Time Statistics Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.13. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attackers to ins...
- CVSS:
- 8.8
- Affected:
- up to 2.13
- Fixed in:
- 3.1
- Disclosed:
- Apr 22, 2021
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 2.12
unknown
Arbitrary Plugin Installation and Activation vulnerability discovered by Bugbang in WordPress Visitor Traffic Real Time Statistics plugin (versions <= 2.11).
- Affected:
- up to 2.12
- Fixed in:
- 2.12
- Disclosed:
- Apr 22, 2021
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 3.1
unknown
The Visitor Traffic Real Time Statistics Plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.13. This is due to missing or incorrect nonce validation on the 'cp_plugins_do_button_job_later_callback' AJAX action. This makes it possible for unauthenticated attackers to ins...
- Affected:
- up to 3.1
- Fixed in:
- 3.1
- Disclosed:
- Apr 22, 2021
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 1.13
unknown
[en] The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.
- Affected:
- up to 1.13
- Fixed in:
- 1.13
- Disclosed:
- Aug 30, 2019
CVE-2019-15831 on NVD →
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 1.14
unknown
[en] The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.
- Affected:
- up to 1.14
- Fixed in:
- 1.14
- Disclosed:
- Aug 30, 2019
CVE-2019-15832 on NVD →
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 1.13
unknown
Cross-Site Request Forgery (CSRF) vulnerability leading to Stored XSS/SQLi vulnerabilities found by Paul Dannewitz in WordPress Visitors Traffic Real Time Statistics plugin (versions <= 1.12).
- Affected:
- up to 1.13
- Fixed in:
- 1.13
- Disclosed:
- Jul 4, 2019
Visitor Traffic Real Time Statistics <= 1.13 - Cross-Site Request Forgery
high
The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.
- CVSS:
- 8.8
- Affected:
- up to 1.13
- Fixed in:
- 1.14
- Disclosed:
- Jul 3, 2019
CVE-2019-15832 on NVD →
Visitor Traffic Real Time Statistics <= 1.12 - Cross-Site Request Forgery
high
The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.
- CVSS:
- 8.8
- Affected:
- up to 1.12
- Fixed in:
- 1.13
- Disclosed:
- Jul 3, 2019
CVE-2019-15831 on NVD →
Visitor Traffic Real Time Statistics [visitors-traffic-real-time-statistics] < 2.13
unknown
The "cp_plugins_do_button_job_later_callback" AJAX action, from multiple plugins of the WP-Buy vendor, was lacking CSRF check, allowing attackers to make a logged in administrator install and active arbitrary plugins (including specific version) from the WordPress repository which could lead to more critical...
- Affected:
- up to 2.13
- Fixed in:
- 2.13
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database