Hitsteps Web Analytics
Hitsteps Web Analytics has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.4 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
Every one of the 2 issues recorded for Hitsteps Web Analytics has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Hitsteps Web Analytics is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2023-45057Hitsteps Web Analytics <= 5.86 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Hitsteps Web Analytics
Author
Hitsteps
Hitsteps is a real-time visitor tracking plugin for WordPress. Watch live visitors, follow page-by-page journeys, and connect behavior to referrers, campaigns, devices, approximate locations, and returning visitor profiles. Add visitor tracking without editing your theme. Connect an account in the plugin settings, save the API key, then verify real-time tracking as soon as the first live visit arrives. See more than aggregate pageview totals by following the journeys behind them. Use Hitsteps to answer practical questions: Who is visiting my WordPress site right now, and which page are they viewing? Which referrers, traffic sources, campaigns, and landing pages bring engaged visitors? What did a visitor view before placing an order, submitting a form, or starting live chat? Which links, buttons, menus, products, and page sections receive clicks in heatmaps? Did traffic stop after a deployment, cache change, or outage? Real-Time Visitor Tracking for WordPress Hitsteps adds the tracking code after you connect an account and API key. The live dashboard shows active and recent visitors without a next-day wait. Live Visitors and Page-by-Page Journeys Follow activity page by page. See current and entry pages, session duration, browser, device, country, region, and available approximate IP-based city context. Visitor Profiles and Returning Visitors Visitor profiles connect repeat browser visits and journey history. Optional aliasing can associate a known identifier supplied after login, form submission, chat, or purchase. Anonymous visits do not reveal a person’s identity automatically. Referrer Analytics and Traffic Sources Connect journeys to available referrers, search engines, campaigns, landing pages, and entry sources. Browsers, privacy controls, apps, and copied links can omit referral data. WordPress Heatmaps and Page Analysis Click heatmaps and Page Analysis show which links, buttons, menus, products, and page sections receive attention, helping explain where journeys stall. WooCommerce and Form Visitor Context Hitsteps can add recent visitor journeys to WooCommerce admin order emails and supported form notifications. Integrations include Contact Form 7, Gravity Forms, Ninja Forms, and Jetpack Contact Form. More Hitsteps Features Live chat and support-button options. Bot detection and referral-spam filtering. Invisible tracking with no public counter badge. Real-visitor page-speed reporting. Uptime monitoring and alert channels, depending on plan and configuration. WordPress dashboard summaries, visitor maps, recent graphs, Online Visual live visitor paths, and pageview widgets. Optional registered-user aliasing across devices when your site has the required permission or consent. Learn more on the Hitsteps features page. External Service and Privacy This plugin connects WordPress to the hosted Hitsteps analytics service. An account and API key are required. It sends analytics data such as page URLs and titles, referrers, browser and device information, IP-derived approximate location, and interactions. Optional aliasing, WooCommerce, or form integrations can also send identity or journey context. Site owners are responsible for providing any notice and obtaining any consent required for their use of analytics, cookies, identity features, chat, and related integrations. Review the Hitsteps Terms of Service and Hitsteps Privacy Policy before enabling the service. Security Policy Reporting Security Bugs Please report security issues in the Hitsteps plugin through the Patchstack Vulnerability Disclosure Program. Patchstack can assist with verification, CVE assignment, and developer notification.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C