Visitor Logic Lite Plugin Vulnerability

HIGH (8.1)

Threat Intelligence

Low Risk
EPSS Score: 0.07% chance of exploitation (percentile: 22%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: No public exploits found

How we test →

What is it?

The Visitor Logic Lite plugin for WordPress is a popular add-on used to enhance the functionality of WordPress websites. This vulnerability allows attackers to inject malicious PHP code into the website, potentially leading to unauthorized access, data theft, or system compromise.

Am I affected?

You're affected if you use Visitor Logic Lite. Specific version info not stated in the advisory.

Affected Products

Visitor Logic / Visitor Logic Lite plugin for WordPress

How to fix

  1. Upgrade: Update Visitor Logic Lite to version 1.0.4 or later from the WordPress Plugin Directory (https://wordpress.org/plugins/visitor-logic-lite/).
  2. Immediate Mitigation: Immediately restrict network access to your website's PHP files and logs (e.g., by configuring your web server to deny access to these directories).