PT-2026-104513 · WordPress · Visitors-Traffic-Real-Time-Statistics
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Visitor Traffic Real Time Statistics plugin for WordPress versions prior to 8.17
Description
Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored DOM-Based Cross-Site Scripting. An attacker can inject arbitrary web scripts by sending a forged
X-Real-IP HTTP header to the wp ajax nopriv ahcfree track visitor endpoint. The payload is stored verbatim in the database and executes whenever a user accesses the affected page.Recommendations
Update the Visitor Traffic Real Time Statistics plugin for WordPress to version 8.17 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Visitors-Traffic-Real-Time-Statistics