high · CVSS v3 7.2
CVE-2026-93367
The Visitors Traffic Real Time Statistics Pro plugin for WordPress has an unauthenticated stored XSS flaw that allows attackers to inject Ja
Overview
The Visitors Traffic Real Time Statistics Pro plugin for WordPress has an unauthenticated stored XSS flaw that allows attackers to inject JavaScript via the page_title parameter. The vulnerability is triggered when an admin views the plugin dashboard, causing arbitrary code to execute in the admin’s browser. This flaw can be exploited without authentication and can lead to session hijacking or defacement.
Description
The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session.
Impact
Confidentiality: attackers can steal admin session cookies or other sensitive data. Integrity: malicious scripts can modify dashboard content or inject malicious links. Availability: repeated exploitation may degrade user experience. The primary impact is on WordPress site administrators who use the plugin.
Remediation
Update the plugin to the latest version (>=11.23) where input is sanitized and output escaped. If an update is not possible, disable the ahcpro_track_visitor AJAX endpoint for unauthenticated users or restrict access via a firewall rule. Additionally, apply a web application firewall rule to block suspicious payloads in the page_title field.
Risk context
Severity is high with a CVSS v3 score of 7.2. The flaw is exploitable by unauthenticated users and can affect any WordPress site running the plugin. Prompt remediation is recommended to prevent potential credential theft or defacement.
Affected products
- WordPress
- Visitors Traffic Real Time Statistics Pro
Scores
- Severity
- high
- CVSS v2
- 6.4
- CVSS v3
- 7.2
- CVSS v4
- —
- EPSS
- —