PT-2026-104513 · WordPress · Visitors-Traffic-Real-Time-Statistics

·

CVE-2026-97341

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Visitor Traffic Real Time Statistics plugin for WordPress versions prior to 8.17
Description Insufficient input sanitization and output escaping allow unauthenticated attackers to perform Stored DOM-Based Cross-Site Scripting. An attacker can inject arbitrary web scripts by sending a forged X-Real-IP HTTP header to the wp ajax nopriv ahcfree track visitor endpoint. The payload is stored verbatim in the database and executes whenever a user accesses the affected page.
Recommendations Update the Visitor Traffic Real Time Statistics plugin for WordPress to version 8.17 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97341

Affected Products

Visitors-Traffic-Real-Time-Statistics