WP Visitor Statistics (Real Time Traffic) <= 8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height' Shortcode Attribute
medium
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wsm_showDayStatsGraph' shortcode in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...
- CVSS:
- 6.4
- Affected:
- up to 8.4
- Fixed in:
- 8.5
- Disclosed:
- Apr 7, 2026
CVE-2026-4303 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] <= 8.3 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows DOM-Based XSS.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 8.3.
- Affected:
- up to 8.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-67983 on NVD →
Visitor Statistics (Real Time Traffic) <= 8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary...
- CVSS:
- 6.4
- Affected:
- up to 8.3
- Fixed in:
- 8.4
- Disclosed:
- Dec 15, 2025
CVE-2025-67983 on NVD →
WP Visitor Statistics (Real Time Traffic) <= 8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitra...
- CVSS:
- 6.4
- Affected:
- up to 8.2
- Fixed in:
- 8.3
- Disclosed:
- Aug 20, 2025
CVE-2025-49400 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 8.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 8.2.
- Affected:
- up to 8.3
- Fixed in:
- 8.3
- Disclosed:
- Aug 20, 2025
CVE-2025-49400 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 7.9
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.8.
- Affected:
- up to 7.9
- Fixed in:
- 7.9
- Disclosed:
- Jul 4, 2025
CVE-2025-53566 on NVD →
WP Visitor Statistics (Real Time Traffic) <= 7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arb...
- CVSS:
- 6.4
- Affected:
- up to 7.8
- Fixed in:
- 7.9
- Disclosed:
- Jul 3, 2025
CVE-2025-53566 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] <= 7.8 (unfixed)
unknown
[en] Missing Authorization vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.8.
- Affected:
- up to 7.8
- Fix:
- No patched version reported
- Disclosed:
- Jun 20, 2025
CVE-2025-49996 on NVD →
WP Visitor Statistics (Real Time Traffic) <= 8.4 - Missing Authorization
medium
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 8.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 8.4
- Fixed in:
- 8.5
- Disclosed:
- Jun 19, 2025
CVE-2025-49996 on NVD →
WP Visitor Statistics (Real Time Traffic) <= 7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitra...
- CVSS:
- 6.4
- Affected:
- up to 7.2
- Fixed in:
- 7.3
- Disclosed:
- Jan 24, 2025
CVE-2025-24675 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 7.3
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.2.
- Affected:
- up to 7.3
- Fixed in:
- 7.3
- Disclosed:
- Jan 24, 2025
CVE-2025-24675 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 7.6
unknown
[en] Missing Authorization vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.3.
- Affected:
- up to 7.6
- Fixed in:
- 7.6
- Disclosed:
- Jan 7, 2025
CVE-2025-22304 on NVD →
WP Visitor Statistics (Real Time Traffic) <= 7.5 - Missing Authorization
medium
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action...
- CVSS:
- 4.3
- Affected:
- up to 7.5
- Fixed in:
- 7.6
- Disclosed:
- Jan 6, 2025
CVE-2025-22304 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 6.9.5
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Osamaesh WP Visitor Statistics (Real Time Traffic).This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 6.9.4.
- Affected:
- up to 6.9.5
- Fixed in:
- 6.9.5
- Disclosed:
- Mar 17, 2024
CVE-2024-24867 on NVD →
WP Visitor Statistics (Real Time Traffic) <= 6.9.4 - Sensitive Information Exposure via Log File
medium
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.9.4. This makes it possible for unauthenticated attackers to extract sensitive data from log files.
- CVSS:
- 5.3
- Affected:
- up to 6.9.4
- Fixed in:
- 6.9.5
- Disclosed:
- Feb 2, 2024
CVE-2024-24867 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 6.9
unknown
[en] The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
- Affected:
- up to 6.9
- Fixed in:
- 6.9
- Disclosed:
- May 15, 2023
CVE-2023-0600 on NVD →
WP Visitor Statistics (Real Time Traffic) <= 6.8.1 - Unauthenticated SQL Injection
critical
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to time-based blind SQL Injection via an unknown parameter in versions up to, and including, 6.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...
- CVSS:
- 9.8
- Affected:
- up to 6.8.1
- Fixed in:
- 6.9
- Disclosed:
- Apr 24, 2023
CVE-2023-0600 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 6.5
unknown
[en] The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.5 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
- Affected:
- up to 6.5
- Fixed in:
- 6.5
- Disclosed:
- Feb 13, 2023
CVE-2022-4656 on NVD →
WP Visitor Statistics (Real Time Traffic) <= 6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The WP Visitor Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level...
- CVSS:
- 6.4
- Affected:
- up to 6.4
- Fixed in:
- 6.5
- Disclosed:
- Jan 17, 2023
CVE-2022-4656 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 5.8
unknown
[en] Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.
- Affected:
- up to 5.8
- Fixed in:
- 5.8
- Disclosed:
- Jul 25, 2022
CVE-2022-33965 on NVD →
WP Visitor Statistics (Real Time Traffic) <= 5.7 - Unauthenticated SQL Injection
critical
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to SQL Injection via the 'refUrl' parameter in versions up to, and including, 5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthe...
- CVSS:
- 9.8
- Affected:
- up to 5.7
- Fixed in:
- 5.8
- Disclosed:
- Jul 6, 2022
CVE-2022-33965 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 5.6
unknown
[en] The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection
- Affected:
- up to 5.6
- Fixed in:
- 5.6
- Disclosed:
- Mar 7, 2022
CVE-2022-0410 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 5.5
unknown
[en] The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude. Furthermore, due to the...
- Affected:
- up to 5.5
- Fixed in:
- 5.5
- Disclosed:
- Feb 28, 2022
CVE-2021-25042 on NVD →
WP Visitor Statistics (Real Time Traffic) <= 5.5 - SQL Injection
high
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection
- CVSS:
- 8.8
- Affected:
- up to 5.6
- Fixed in:
- 5.6
- Disclosed:
- Feb 14, 2022
CVE-2022-0410 on NVD →
WP Visitor Statistics (Real Time Traffic) <= 5.4 - Missing Authorization to Stored Cross-Site Scripting
medium
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude. Furthermore, due to the lack...
- CVSS:
- 5.4
- Affected:
- up to 5.4
- Fixed in:
- 5.5
- Disclosed:
- Jan 31, 2022
CVE-2021-25042 on NVD →
WP Visitor Statistics (Real Time Traffic) <= 4.7 - SQL Injection
high
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks
- CVSS:
- 8.8
- Affected:
- up to 4.8
- Fixed in:
- 4.8
- Disclosed:
- Dec 22, 2021
CVE-2021-24750 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 4.8
unknown
[en] The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks
- Affected:
- up to 4.8
- Fixed in:
- 4.8
- Disclosed:
- Dec 21, 2021
CVE-2021-24750 on NVD →
WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 6.9.5
unknown
- Affected:
- up to 6.9.5
- Fixed in:
- 6.9.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database