Executive brief
Visitor Traffic Real Time Statistics Pro is a WordPress plugin used to track and display visitor analytics on websites. An unauthenticated SQL injection vulnerability allows attackers to read, modify, or delete the entire website database without needing to log in, including user accounts and sensitive data. This poses a critical risk to WordPress sites using vulnerable versions.
Technical details
This is an unauthenticated SQL injection vulnerability in Visitor Traffic Real Time Statistics Pro versions 11.17 and earlier. The vulnerable component fails to properly sanitize user input before constructing database queries, allowing attackers to inject arbitrary SQL commands via the network without requiring authentication or user interaction. An attacker can query, modify, or delete database contents including user credentials and private data. The vulnerability has been patched in version 11.18 and later.
Affected products
- WordPress Visitor Traffic Real Time Statistics Pro 11.17 and earlier
Timeline
- 2026-08-25: disclosed
- 2026-08-27: advisory
- 2026-08-25: patched: Fixed in version 11.18