Unauthenticated Stored Cross-Site Scripting in Visitors Traffic Real Time Statistics Pro for WordPress
CVE-2026-93367
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 2 October 2026
What is CVE-2026-93367?
The Visitors Traffic Real Time Statistics Pro plugin for WordPress contains a vulnerability that permits unauthenticated stored Cross-Site Scripting (XSS). This issue arises from the mismanagement of the 'page_title' parameter in the ahcpro_track_visitor AJAX action, which is accessible to logged-out users. The plugin fails to sanitize input, enabling attackers to store malicious JavaScript code in the database. When an administrator accesses the plugin's dashboard, the vulnerable DataTable renders this unsanitized data as raw HTML, leading to the execution of the injected scripts in the administrator's session. This flaw poses a significant security threat, allowing unauthorized individuals to potentially compromise administrator accounts.
Affected Version(s)
Visitor Traffic Real Time Statistics pro 0 <= 11.22