Title: Security Issue
Last modified: September 12, 2026

---

# Security Issue

 *  Resolved [willnev](https://wordpress.org/support/users/willnev/)
 * (@willnev)
 * [3 weeks, 2 days ago](https://wordpress.org/support/topic/security-issue-202/)
 * Hi – I received a warning that there is a security issue with this plugin. Any
   idea on when a fix will be deployed?

Viewing 11 replies - 1 through 11 (of 11 total)

 *  Plugin Author [Denis Botić](https://wordpress.org/support/users/strongetic/)
 * (@strongetic)
 * [3 weeks ago](https://wordpress.org/support/topic/security-issue-202/#post-19016556)
 * Hi, 
   thank you for bringing this to my attention.I will look into this issue 
   immediately and work on a fix as soon as possible. I’ll keep you updated here.
   Denis Botic
 *  Thread Starter [willnev](https://wordpress.org/support/users/willnev/)
 * (@willnev)
 * [3 weeks ago](https://wordpress.org/support/topic/security-issue-202/#post-19016610)
 * Thank you for your quick response! I appreciate you looking into it.
 *  Plugin Author [Denis Botić](https://wordpress.org/support/users/strongetic/)
 * (@strongetic)
 * [3 weeks ago](https://wordpress.org/support/topic/security-issue-202/#post-19016980)
 * I am currently working on a fix and reviewing the code. 
   To help me pinpoint 
   the exact issue, could you share the precise security message or log you received?
   I ask because there are three specific things in the code that automated scanners
   sometimes falsely flag as issues, and I have already included security description
   comments explaining why they are safe. Aside from those, I found two other low-
   risk areas and have already bulletproofed them.Having the exact message will 
   help me confirm if the report is referring to a false positive or something else
   entirely. Thank you for your help!
 *  Thread Starter [willnev](https://wordpress.org/support/users/willnev/)
 * (@willnev)
 * [3 weeks ago](https://wordpress.org/support/topic/security-issue-202/#post-19016982)
 * Understood and thank you for working so quickly on this! Below is a link to the
   PatchStack post regarding the issue.
   [https://patchstack.com/database/wordpress/plugin/page-visits-counter-lite/vulnerability/wordpress-page-visits-counter-lite-plugin-1-2-3-cross-site-scripting-xss-vulnerability](https://patchstack.com/database/wordpress/plugin/page-visits-counter-lite/vulnerability/wordpress-page-visits-counter-lite-plugin-1-2-3-cross-site-scripting-xss-vulnerability)
 *  Plugin Author [Denis Botić](https://wordpress.org/support/users/strongetic/)
 * (@strongetic)
 * [3 weeks ago](https://wordpress.org/support/topic/security-issue-202/#post-19017039)
 * Thank you for providing the link! This gives me exactly what I need.
 * **You can completely relax and continue using the plugin safely.** This report
   is essentially a technical false positive caused by how automated security scanners
   work. They flag code if it doesn’t strictly use specific WordPress escaping functions
   before outputting data, even if the data itself is already completely secure.
 * Here is why your site is 100% safe from this right now:
    - **No Frontend User Input:** The plugin does not send or accept any data from
      regular frontend visitors after the page loads.
    - **Protected Data Sources:** The data displayed by the plugin consists of standard
      WordPress post titles, page names, or WooCommerce products. Only logged-in
      users with high-level administrative privileges can create these titles in
      the first place, and WordPress natively sanitizes them.
    - **Strict Integer Formatting:** The only data an administrator can input directly
      related to the plugin are visit numbers, which are strictly forced to be integers(
      numbers) before being saved to the database. There is simply no entry point
      for malicious scripts.
 * **What’s next?**
   Even though there is no real-world security vulnerability here,
   I want to keep the automated scanners happy so you don’t have to see these warnings.
   I am wrapping up a security update over the weekend and plan to publish the new
   version by Monday. This update will implement explicit escaping functions to 
   clear this notice from Patchstack entirely.
 * Thank you again for your patience and for helping keep the plugin safe!
 *  Thread Starter [willnev](https://wordpress.org/support/users/willnev/)
 * (@willnev)
 * [2 weeks, 6 days ago](https://wordpress.org/support/topic/security-issue-202/#post-19017846)
 * That’s great! Thank you so much for the reassurance and the updates you’ll be
   pushing out. It’s great;y appreciated!
 *  Moderator [Steven Stern (sterndata)](https://wordpress.org/support/users/sterndata/)
 * (@sterndata)
 * Volunteer Forum Moderator
 * [2 weeks, 4 days ago](https://wordpress.org/support/topic/security-issue-202/#post-19018978)
 * [@willnev](https://wordpress.org/support/users/willnev/) I’ve removed your post
   because it details an exploit. Not something that should be widely distributed.
   [@strongetic](https://wordpress.org/support/users/strongetic/) , please give 
   them a private way of contacting you if you’re interested in this info.
 *  Plugin Author [Denis Botić](https://wordpress.org/support/users/strongetic/)
 * (@strongetic)
 * [2 weeks, 3 days ago](https://wordpress.org/support/topic/security-issue-202/#post-19019699)
 * **Hi everyone,**
 * **Thank you for reporting this issue and for your patience.**
 * I sincerely apologize for the inconvenience. Due to a deployment glitch during
   last night’s update, a few crucial files (including `class-export-csv.php`) failed
   to transfer from my local environment to the WordPress repository. This is what
   caused the `Fatal Error` on your websites.
 * I am already actively working on a fix. You might see a few minor version updates
   rolling out shortly as I test the deployment. **Please do not update or download
   the plugin until I post a confirmation here that it is completely safe to do 
   so.**
 * I will update this thread the exact moment the stable fix is live. Thank you 
   for your understanding!
 *  Thread Starter [willnev](https://wordpress.org/support/users/willnev/)
 * (@willnev)
 * [2 weeks, 3 days ago](https://wordpress.org/support/topic/security-issue-202/#post-19019726)
 * Thank you!
 *  Thread Starter [willnev](https://wordpress.org/support/users/willnev/)
 * (@willnev)
 * [2 weeks, 3 days ago](https://wordpress.org/support/topic/security-issue-202/#post-19019727)
 * [@strongetic](https://wordpress.org/support/users/strongetic/) – Thank you! Totally
   understand! Thank you!
 *  Plugin Author [Denis Botić](https://wordpress.org/support/users/strongetic/)
 * (@strongetic)
 * [2 weeks, 3 days ago](https://wordpress.org/support/topic/security-issue-202/page/2/#post-19020107)
 * **UPDATE: The stable fix is now live (Version 2.0.5)!**
 * I am happy to confirm that **Version 2.0.5** is fully safe, stable, and includes
   the necessary security update. If your website was affected by the fatal error,
   updating to this version will resolve the issue and bring your site back online.
 * I want to thank all of you so much for your incredible patience and understanding.
   I also wanted to explain why this fix took a bit longer to appear: after pushing
   the corrected code to the official WordPress repository, we had to wait about
   6 hours for WordPress to complete all its automated security scans and reviews.
   Only after those checks were successful did WordPress make the update available
   in your WP admin dashboards.
 * What you need to do now:
    - **If your site has automatic updates enabled:** It should automatically pull
      Version 2.0.5 and fix itself within the next few hours (once your site’s WordPress
      cron job runs).
    - **If you can access your WP Admin dashboard:** Please go to _Plugins > Installed
      Plugins_ and manually click **Update** on this plugin.
    - **If your website is still showing a blank screen (Fatal Error) and you cannot
      access the dashboard:**
       1. Log into your server via FTP or cPanel File Manager.
       2. Navigate to `wp-content/plugins/` and delete or rename the folder of this
          plugin (this will bring your site back instantly).
       3. Log back into your WP Admin, download Version 2.0.5 from the plugin repository,
          and activate it.
 * Thank you again for standing by me while I resolved this. Please let me know 
   if everything is back to normal on your end!
 * Best regards,
   Denis Botić

Viewing 11 replies - 1 through 11 (of 11 total)

You must be [logged in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fwordpress.org%2Fsupport%2Ftopic%2Fsecurity-issue-202%2F%3Foutput_format%3Dmd&locale=en_US)
to reply to this topic.

 * ![](https://ps.w.org/page-visits-counter-lite/assets/icon-256x256.png?rev=2501212)
 * [Page Visits Counter - Lite](https://wordpress.org/plugins/page-visits-counter-lite/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/page-visits-counter-lite/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/page-visits-counter-lite/)
 * [Active Topics](https://wordpress.org/support/plugin/page-visits-counter-lite/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/page-visits-counter-lite/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/page-visits-counter-lite/reviews/)

 * 16 replies
 * 3 participants
 * Last reply from: [Denis Botić](https://wordpress.org/support/users/strongetic/)
 * Last activity: [2 weeks, 3 days ago](https://wordpress.org/support/topic/security-issue-202/page/2/#post-19020107)
 * Status: resolved