SRS Simple Hits Counter
SRS Simple Hits Counter has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2023; all 2 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include SQL Injection.
Every one of the 2 issues recorded for SRS Simple Hits Counter has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. SRS Simple Hits Counter is installed on roughly 8,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.0.
CVE-2020-5766SRS Simple Hits Counter Plugin for WordPress 1.03 - 1.04 - Unauthenticated SQL Injection
Read the full analysisVulnerability Records

SRS Simple Hits Counter
Author
SandyRig
SRS Simple Hits Counter is a simple, very lightweight visitor counter plugin for WordPress that tracks Unique Visitors and Page-views — without causing render blocking or straining your site. You can display your visitor counter anywhere on your site using widgets or shortcodes. Show Unique Visitors, Page-views, or both — just use two copies of the widget or shortcode to display both counters together. Note: The counter keeps running in the background even when no widget or shortcode is active. To completely stop counting, you need to disable the plugin. Features AJAX based counter ignores most bots or crawlers Monthly and weekly graph in admin Show the Unique Visitors, Page-views count or both Ability to reset the counter to any number any time Can be shown anywhere on the site using Widgets and Shortcode Counter works and shows data in admin even when no widget or short-code is active SHORTCODES [srs_total_visitors] for Unique Visitors [srs_total_pageViews] for Page-views DEMO
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C