Unauthenticated Cross Site Scripting in Visitor Traffic Real Time Statistics Pro Plugin
CVE-2026-57370
7.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 July 2026
What is CVE-2026-57370?
An unauthenticated Cross Site Scripting (XSS) vulnerability has been identified in the Visitor Traffic Real Time Statistics Pro plugin for WordPress. This flaw exists in versions up to and including 11.9.1, allowing attackers to inject malicious scripts via crafted input. If successfully exploited, this could lead to unauthorized actions performed on behalf of unsuspecting users, compromising their security and privacy. It is crucial for users of the affected plugin to update to the latest version to mitigate risks associated with this vulnerability.
Affected Version(s)
Visitor Traffic Real Time Statistics Pro <= 11.9.1