The plugin does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
id: CVE-2023-0600
info:
name: WP Visitor Statistics (Real Time Traffic) < 6.9 - SQL Injection
a
...