← WordPress Vulnerabilities
WordPress security by component

Visitor Traffic Real Time Statistics

Visitor Traffic Real Time Statistics is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Apr 04, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: visitor-traffic-real-time-statistics

CVE-2026-2936: Visitor Traffic Real Time Statistics: Cross-site scripting

Visitor Traffic Real Time Statistics is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 8.4.

PublishedApr 04, 2026
Known safe version> 8.4
Safe version
Apr 04, 2026 CVE-2026-2936
Visitor Traffic Real Time Statistics: Cross-site scripting
Visitor Traffic Real Time Statistics is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 8.4.
> 8.4
CVE7.2
NVDPending
Nov 08, 2021 CVE-2021-24829
Visitor Traffic Real Time Statistics: SQL injection
Visitor Traffic Real Time Statistics is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
May 14, 2021 CVE-2021-24193
AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics: A security weakness
AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVD8.8