Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-96267— WP Visitor Statistics (Real Time Traffic) <= 8.7 - Unauthenticated SQL Injection via 'fullRef' Parameter

Quick assessment

Affected
osamaesh WP Visitor Statistics (Real Time Traffic)
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 WP Visitor Statistics(实时流量)在 8.7 及以下所有版本中存在通用 SQL 注入漏洞,原因是未对用户提供的参数 进行充分的转义,且现有 SQL 查询缺乏适当的预处理。这使得未经身份验证的攻击者能够将额外的 SQL 查询注入到已有的查询中,从而从数据库中提取敏感信息。 该漏洞属于二阶 SQL 注入:未经身份验证的攻击者向 跟踪端点提交一个精心构造的 Referer URL,该 URL 的原始未转义值会被持久化存储到 表中。当管理员下次访问“流量来源”(Traffic

CVSS 7.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-96267

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
WP Visitor Statistics (Real Time Traffic) <= 8.7 - Unauthenticated SQL Injection via 'fullRef' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection: an unauthenticated attacker submits a crafted referrer URL to the wmcTrack tracking endpoint, which persists the raw unescaped value into the wp_logVisit table, and the injection is triggered when an administrator next views the Traffic Sources dashboard.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
osamaesh WP Visitor Statistics (Real Time Traffic) 0 ~ 8.7 -

II. Public POCs for CVE-2026-96267

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-96267

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-96267 (2)

Vendor Advisories for CVE-2026-96267 (1)

Other References for CVE-2026-96267 (1)

Other References for CVE-2026-96267 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-96267

No comments yet


Leave a comment