Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session. | |
| Title | Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-10-02T03:38:46.638Z
Reserved: 2026-09-17T18:58:09.010Z
Link: CVE-2026-93367
No data.
Status : Deferred
Published: 2026-10-02T04:18:09.573
Modified: 2026-10-02T13:18:55.613
Link: CVE-2026-93367
No data.
OpenCVE Enrichment
Updated: 2026-10-02T05:00:14Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')