Medium 6.4
2026-04-08< 8.5
WP Visitor Statistics (Real Time Traffic) <= 8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height' Shortcode Attribute
Minimum safe version
8.5
Update to 8.5 or later to address 15 fixable vulnerabilities
WP Visitor Statistics (Real Time Traffic) <= 8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'height' Shortcode Attribute
CVE-2025-67983
PressApps Knowledge Base Contextual Sidebar Addon <= 4.2.1 - Unauthenticated PHP Object Injection
CVE-2025-53566
CVE-2025-49996
CVE-2025-24675
CVE-2025-22304
CVE-2024-24867
CVE-2023-0600
CVE-2022-4656
CVE-2022-33965
WP Visitor Statistics (Real Time Traffic) <= 4.7 - SQL Injection
CVE-2021-25042
CVE-2022-0410