CVE-2026-93367
Received Received - Intake

Stored XSS in Visitors Traffic Real Time Statistics Pro WordPress Plugin

Vulnerability report for CVE-2026-93367, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Wordfence

Description

The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp-buy visitors_traffic_real_time_statistics_pro to 11.22 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated stored Cross-Site Scripting (XSS) flaw in the Visitors Traffic Real Time Statistics Pro WordPress plugin. It allows attackers to inject malicious scripts via the page_title parameter in the ahcpro_track_visitor AJAX action. The injected scripts are stored without sanitization and executed when an administrator views the plugin's dashboard, potentially compromising administrator sessions.

Detection Guidance

Check WordPress sites for the Visitors Traffic Real Time Statistics Pro plugin versions up to 11.22. Look for suspicious entries in the ahc_title_traffic.til_page_title column of the database. Monitor for unauthorized admin actions or unexpected JavaScript execution in the plugin's Traffic by Title dashboard.

Impact Analysis

If exploited, this vulnerability could allow attackers to steal sensitive session cookies, perform actions on behalf of administrators, or inject further malicious code into the website. It may lead to unauthorized access, data breaches, or defacement of the site. Users with administrative privileges are particularly at risk.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by enabling unauthorized access to personal data or sensitive information. If exploited, it may result in data breaches that violate privacy regulations, potentially leading to legal penalties, reputational damage, and loss of user trust.

Mitigation Strategies

Immediately update the Visitors Traffic Real Time Statistics Pro plugin to the latest version. If no update is available, disable and remove the plugin until a patch is released. Review database entries for the ahc_title_traffic.til_page_title column for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93367. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart