Executive brief
A vulnerability in the Visitor Traffic Real Time Statistics Pro plugin for WordPress allows unauthorized attackers to inject malicious scripts into the website. This occurs when a site administrator or visitor clicks on a specially crafted link, potentially leading to unauthorized actions, data theft, or website defacement. Site owners should update to version 11.9.2 immediately to protect their users and reputation.
Technical details
The Visitor Traffic Real Time Statistics Pro plugin for WordPress (versions <= 11.9.1) is vulnerable to reflected Cross-Site Scripting (XSS) due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a malicious link or visiting a crafted URL. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, which can be used to hijack administrative sessions or redirect users to malicious sites. The issue is resolved in version 11.9.2.
Affected products
- CODEPRESS IT Solutions LLC Visitor Traffic Real Time Statistics Pro <= 11.9.1
Timeline
- 2026-05-19: other: Reported by researcher dutafi
- 2026-07-07: advisory: Patchstack advisory published
- 2026-07-23: disclosed: CVE published to NVD