CVE-2026-32479: WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.17 - SQL Injection vulnerability
Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Visitor Traffic Real Time Statistics Pro pluginto a version that resolves this vulnerability.Fixed in 11.18
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The issue is exploitable remotely over the network without authentication, user interaction, or elevated privileges. The attack complexity is rated low.
Which installations should be treated as affected?
Installations using WordPress Visitor Traffic Real Time Statistics Pro version 11.17 or earlier should be treated as affected based on the available information.
What is the expected security impact if exploitation succeeds?
The supplied severity vector indicates high confidentiality impact and low availability impact, with no integrity impact indicated. It also indicates scope can be changed.