Stored DOM-Based Cross-Site Scripting Vulnerability in Visitor Traffic Real Time Statistics Plugin for WordPress
CVE-2026-97341
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-97341?
The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting. This vulnerability arises from inadequate input sanitization and output escaping in the way it handles the 'X-Real-IP' HTTP Header. Attackers can exploit this flaw to inject arbitrary web scripts that execute upon user access to the compromised page. This risk is particularly concerning as it requires no authentication, nonce, or specific capabilities; the wp_ajax_nopriv_ahcfree_track_visitor endpoint accepts the maliciously crafted X-Real-IP header and stores the potentially harmful payload directly in the database.
Affected Version(s)
Visitor Traffic Real Time Statistics 0 <= 8.16