Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Visitor Statistics HIGH 7.5
CVE-2024-24867

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Osamaesh WP Visitor Statistics (Real Time Traffic).This issue affects WP …

Fix: after 6.9.4
Fix from $1,950 2024-03-17
Visitor Statistics CRITICAL 9.8
CVE-2023-0600

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing …

Fix: 6.9+
Fix from $2,300 2023-05-15
Visitor Statistics MEDIUM 5.4
CVE-2022-4656

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.5 does not validate and escape one of its shortcode attributes, which could a…

Fix: 6.5+
Fix from $1,600 2023-02-13
Visitor Statistics CRITICAL 9.8
CVE-2022-33965

Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.

Fix: 5.8+
Fix from $2,300 2022-07-25
Visitor Statistics HIGH 8.8
CVE-2022-0410

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL stat…

Fix: 5.6+
Fix from $1,950 2022-03-07
Visitor Statistics MEDIUM 5.4
CVE-2021-25042

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.5 does not have authorisation and CSRF checks in the updateIpAddress AJAX act…

Fix: 5.5+
Fix from $1,600 2022-02-28
Visitor Statistics HIGH 8.8
CVE-2021-24750EPSS 38%

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX act…

Fix: 4.8+
Fix from $1,950 2021-12-21