plugin

Wp Stats Manager Vulnerabilities

28 known security issues reported for the Wp Stats Manager WordPress plugin. Most recent disclosed Apr 7, 2026.

2 critical 2 high 10 medium

Running Wp Stats Manager on your site? Check whether your installed version is affected.

Scan your site free

WP Visitor Statistics (Real Time Traffic) <= 8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height' Shortcode Attribute

medium

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wsm_showDayStatsGraph' shortcode in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for...

CVSS:
6.4
Affected:
up to 8.4
Fixed in:
8.5
Disclosed:
Apr 7, 2026

CVE-2026-4303 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] <= 8.3 (unfixed)

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) wp-stats-manager allows DOM-Based XSS.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through <= 8.3.

Affected:
up to 8.3
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-67983 on NVD →

Visitor Statistics (Real Time Traffic) <= 8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary...

CVSS:
6.4
Affected:
up to 8.3
Fixed in:
8.4
Disclosed:
Dec 15, 2025

CVE-2025-67983 on NVD →

WP Visitor Statistics (Real Time Traffic) <= 8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitra...

CVSS:
6.4
Affected:
up to 8.2
Fixed in:
8.3
Disclosed:
Aug 20, 2025

CVE-2025-49400 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 8.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 8.2.

Affected:
up to 8.3
Fixed in:
8.3
Disclosed:
Aug 20, 2025

CVE-2025-49400 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 7.9

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.8.

Affected:
up to 7.9
Fixed in:
7.9
Disclosed:
Jul 4, 2025

CVE-2025-53566 on NVD →

WP Visitor Statistics (Real Time Traffic) <= 7.8 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 7.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arb...

CVSS:
6.4
Affected:
up to 7.8
Fixed in:
7.9
Disclosed:
Jul 3, 2025

CVE-2025-53566 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] <= 7.8 (unfixed)

unknown

[en] Missing Authorization vulnerability in osama.esh WP Visitor Statistics (Real Time Traffic) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.8.

Affected:
up to 7.8
Fix:
No patched version reported
Disclosed:
Jun 20, 2025

CVE-2025-49996 on NVD →

WP Visitor Statistics (Real Time Traffic) <= 8.4 - Missing Authorization

medium

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 8.4. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 8.4
Fixed in:
8.5
Disclosed:
Jun 19, 2025

CVE-2025-49996 on NVD →

WP Visitor Statistics (Real Time Traffic) <= 7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitra...

CVSS:
6.4
Affected:
up to 7.2
Fixed in:
7.3
Disclosed:
Jan 24, 2025

CVE-2025-24675 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 7.3

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.2.

Affected:
up to 7.3
Fixed in:
7.3
Disclosed:
Jan 24, 2025

CVE-2025-24675 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 7.6

unknown

[en] Missing Authorization vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.3.

Affected:
up to 7.6
Fixed in:
7.6
Disclosed:
Jan 7, 2025

CVE-2025-22304 on NVD →

WP Visitor Statistics (Real Time Traffic) <= 7.5 - Missing Authorization

medium

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 7.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action...

CVSS:
4.3
Affected:
up to 7.5
Fixed in:
7.6
Disclosed:
Jan 6, 2025

CVE-2025-22304 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 6.9.5

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Osamaesh WP Visitor Statistics (Real Time Traffic).This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 6.9.4.

Affected:
up to 6.9.5
Fixed in:
6.9.5
Disclosed:
Mar 17, 2024

CVE-2024-24867 on NVD →

WP Visitor Statistics (Real Time Traffic) <= 6.9.4 - Sensitive Information Exposure via Log File

medium

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.9.4. This makes it possible for unauthenticated attackers to extract sensitive data from log files.

CVSS:
5.3
Affected:
up to 6.9.4
Fixed in:
6.9.5
Disclosed:
Feb 2, 2024

CVE-2024-24867 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 6.9

unknown

[en] The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

Affected:
up to 6.9
Fixed in:
6.9
Disclosed:
May 15, 2023

CVE-2023-0600 on NVD →

WP Visitor Statistics (Real Time Traffic) <= 6.8.1 - Unauthenticated SQL Injection

critical

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to time-based blind SQL Injection via an unknown parameter in versions up to, and including, 6.8.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it pos...

CVSS:
9.8
Affected:
up to 6.8.1
Fixed in:
6.9
Disclosed:
Apr 24, 2023

CVE-2023-0600 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 6.5

unknown

[en] The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.5 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.

Affected:
up to 6.5
Fixed in:
6.5
Disclosed:
Feb 13, 2023

CVE-2022-4656 on NVD →

WP Visitor Statistics (Real Time Traffic) <= 6.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The WP Visitor Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 6.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level...

CVSS:
6.4
Affected:
up to 6.4
Fixed in:
6.5
Disclosed:
Jan 17, 2023

CVE-2022-4656 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 5.8

unknown

[en] Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.

Affected:
up to 5.8
Fixed in:
5.8
Disclosed:
Jul 25, 2022

CVE-2022-33965 on NVD →

WP Visitor Statistics (Real Time Traffic) <= 5.7 - Unauthenticated SQL Injection

critical

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to SQL Injection via the 'refUrl' parameter in versions up to, and including, 5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthe...

CVSS:
9.8
Affected:
up to 5.7
Fixed in:
5.8
Disclosed:
Jul 6, 2022

CVE-2022-33965 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 5.6

unknown

[en] The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection

Affected:
up to 5.6
Fixed in:
5.6
Disclosed:
Mar 7, 2022

CVE-2022-0410 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 5.5

unknown

[en] The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude. Furthermore, due to the...

Affected:
up to 5.5
Fixed in:
5.5
Disclosed:
Feb 28, 2022

CVE-2021-25042 on NVD →

WP Visitor Statistics (Real Time Traffic) <= 5.5 - SQL Injection

high

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection

CVSS:
8.8
Affected:
up to 5.6
Fixed in:
5.6
Disclosed:
Feb 14, 2022

CVE-2022-0410 on NVD →

WP Visitor Statistics (Real Time Traffic) <= 5.4 - Missing Authorization to Stored Cross-Site Scripting

medium

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX action, allowing any authenticated user to call it, or make a logged in user do it via a CSRF attack and add an arbitrary IP address to exclude. Furthermore, due to the lack...

CVSS:
5.4
Affected:
up to 5.4
Fixed in:
5.5
Disclosed:
Jan 31, 2022

CVE-2021-25042 on NVD →

WP Visitor Statistics (Real Time Traffic) <= 4.7 - SQL Injection

high

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CVSS:
8.8
Affected:
up to 4.8
Fixed in:
4.8
Disclosed:
Dec 22, 2021

CVE-2021-24750 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 4.8

unknown

[en] The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

Affected:
up to 4.8
Fixed in:
4.8
Disclosed:
Dec 21, 2021

CVE-2021-24750 on NVD →

WP Visitor Statistics (Real Time Traffic) [wp-stats-manager] < 6.9.5

unknown
Affected:
up to 6.9.5
Fixed in:
6.9.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database