The Advanced Page Visit Counter plugin for WordPress is not secure against malicious attacks. Versions 8.0.6 and earlier are especially vulnerable since they do not properly sanitize user input or escape output. This means that anyone with at least contributor-level access can inject malicious web scripts into pages that will execute when a user visits the page.