Description
WordPress Plugin Visitor Traffic Real Time Statistics is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently install arbitrary plugins. WordPress Plugin Visitor Traffic Real Time Statistics version 2.11 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.12 or latest
References
https://ithemes.com/wordpress-vulnerability-report-april-2021-part-4/
https://plugins.svn.wordpress.org/visitors-traffic-real-time-statistics/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin My WordPress Login Logo Multiple Unspecified Vulnerabilities (2.1)
WordPress Plugin HTML5 Video Player-Best WordPress Video Player and Block SQL Injection (2.5.24)
Jenkins Deserialization of Untrusted Data Vulnerability (CVE-2021-21604)
WordPress Plugin AccessPress Social Icons Multiple SQL Injection Vulnerabilities (1.6.6)