Kama Click Counter
Kama Click Counter has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2017 and 2025; all 4 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 8.1 out of 10. Severity breakdown: 0 critical and 1 high. 2025 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 3 of the records (75%). Other recurring categories include SQL Injection.
Every one of the 4 issues recorded for Kama Click Counter has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by Muhammad Yudha - DJ. Kama Click Counter is installed on roughly 800 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2017-18614Kama Click Counter <= 3.4.9 - Blind SQL Injection
Read the full analysisVulnerability Records
Kama Click Counter
Author
Timur Kamaev
With this plugin, you can gather statistics on clicks for file downloads or any other link across the site. To insert a file download block, use the [download url="any file URL"] shortcode. The plugin does not include additional tools for uploading files. All files must be uploaded using the standard WordPress media uploader. The URLs are then used to create the download block. Additionally, the plugin includes: A button in the visual editor for quickly inserting the file download block shortcode. A customizable widget that allows you to display a list of “Top Downloads” or “Top Link Clicks.”
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C