High severity8.8NVD Advisory· Published May 14, 2021· Updated Jun 17, 2026
CVE-2021-24193
CVE-2021-24193
Description
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <2.12
- wp-buy/Visitor Traffic Real Time Statisticsv5Range: 2.12
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/74889e29-5349-43d1-baf5-1622493be90cnvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.