PT-2026-104074 · Wp Buy · Visitors-Traffic-Real-Time-Statistics

·

CVE-2026-93367

·

Publicado

2026-10-02

·

Atualizado

2026-10-02

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page title parameter of the ahcpro track visitor AJAX action. The action is registered for logged-out callers (wp ajax nopriv ahcpro track visitor) and stores $ POST['page title'] with NO sanitization, keeping it raw in the ahc title traffic.til page title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-93367

Produtos afetados

Visitors-Traffic-Real-Time-Statistics