Unauthenticated Stored Cross-Site Scripting in Visitors Traffic Real Time Statistics Pro for WordPress
CVE-2026-93367

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 October 2026

What is CVE-2026-93367?

The Visitors Traffic Real Time Statistics Pro plugin for WordPress contains a vulnerability that permits unauthenticated stored Cross-Site Scripting (XSS). This issue arises from the mismanagement of the 'page_title' parameter in the ahcpro_track_visitor AJAX action, which is accessible to logged-out users. The plugin fails to sanitize input, enabling attackers to store malicious JavaScript code in the database. When an administrator accesses the plugin's dashboard, the vulnerable DataTable renders this unsanitized data as raw HTML, leading to the execution of the injected scripts in the administrator's session. This flaw poses a significant security threat, allowing unauthorized individuals to potentially compromise administrator accounts.

Affected Version(s)

Visitor Traffic Real Time Statistics pro 0 <= 11.22

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad
.