Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93367— Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)

Quick assessment

Affected
wp-buy Visitor Traffic Real Time Statistics pro
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件“Visitors Traffic Real Time Statistics Pro”存在未认证的存储型跨站脚本(XSS)漏洞,该漏洞影响所有 11.22 及更早版本。攻击者可通过 AJAX 操作的 参数利用此漏洞。该 AJAX 动作已注册为允许未登录用户调用(即 ),并在接收 时未进行任何数据清理,直接以原始形式存储到数据库表 的 字段中。当管理员打开插件的仪表盘时,“按标题查看流量”(Traffic by Title)数据表会以 方式渲染该已存储的值,且未进行输出转义,从而导致任意 Ja

CVSS 7.2 · High EPSS 0.19% · P8

Affected Version Matrix 1

VendorProduct Version RangeStatus
wp-buy Visitor Traffic Real Time Statistics pro ≤ 11.22 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93367

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)
Source: CVE Program / CVE List V5
Vulnerability Description
The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
wp-buy Visitor Traffic Real Time Statistics pro 0 ~ 11.22 -

II. Public POCs for CVE-2026-93367

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93367

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-93367 (1)

Other References for CVE-2026-93367 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-93367

No comments yet


Leave a comment