Stored DOM-Based Cross-Site Scripting Vulnerability in Visitor Traffic Real Time Statistics Plugin for WordPress
CVE-2026-97341

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 October 2026

What is CVE-2026-97341?

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting. This vulnerability arises from inadequate input sanitization and output escaping in the way it handles the 'X-Real-IP' HTTP Header. Attackers can exploit this flaw to inject arbitrary web scripts that execute upon user access to the compromised page. This risk is particularly concerning as it requires no authentication, nonce, or specific capabilities; the wp_ajax_nopriv_ahcfree_track_visitor endpoint accepts the maliciously crafted X-Real-IP header and stores the potentially harmful payload directly in the database.

Affected Version(s)

Visitor Traffic Real Time Statistics 0 <= 8.16

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kuba
.