Description
WordPress Plugin Visitor Traffic Real Time Statistics is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently install arbitrary plugins. WordPress Plugin Visitor Traffic Real Time Statistics version 2.11 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.12 or latest
References
https://ithemes.com/wordpress-vulnerability-report-april-2021-part-4/
https://plugins.svn.wordpress.org/visitors-traffic-real-time-statistics/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin WooCommerce Anti-Fraud Security Bypass (3.2)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall Cross-Site Scripting (4.4.5)
WordPress Plugin Disable Feeds Unspecified Vulnerability (1.4)
Jenkins Other Vulnerability (CVE-2020-2100)
WordPress Plugin GD Star Rating 'export.php' Security Bypass (1.9.18)