rootpwn

high · CVSS v3 7.2

CVE-2026-93367

The Visitors Traffic Real Time Statistics Pro plugin for WordPress has an unauthenticated stored XSS flaw that allows attackers to inject Ja

Overview

The Visitors Traffic Real Time Statistics Pro plugin for WordPress has an unauthenticated stored XSS flaw that allows attackers to inject JavaScript via the page_title parameter. The vulnerability is triggered when an admin views the plugin dashboard, causing arbitrary code to execute in the admin’s browser. This flaw can be exploited without authentication and can lead to session hijacking or defacement.

Description

The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session.

Impact

Confidentiality: attackers can steal admin session cookies or other sensitive data. Integrity: malicious scripts can modify dashboard content or inject malicious links. Availability: repeated exploitation may degrade user experience. The primary impact is on WordPress site administrators who use the plugin.

Remediation

Update the plugin to the latest version (>=11.23) where input is sanitized and output escaped. If an update is not possible, disable the ahcpro_track_visitor AJAX endpoint for unauthenticated users or restrict access via a firewall rule. Additionally, apply a web application firewall rule to block suspicious payloads in the page_title field.

Risk context

Severity is high with a CVSS v3 score of 7.2. The flaw is exploitable by unauthenticated users and can affect any WordPress site running the plugin. Prompt remediation is recommended to prevent potential credential theft or defacement.

Affected products

  • WordPress
  • Visitors Traffic Real Time Statistics Pro

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
—

wordpress xss unauthenticated admin plugin stored defense

← All CVEs