PT-2026-104549 · WordPress · Wp Visitor Statistics
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WP Visitor Statistics (Real Time Traffic) versions prior to 8.8
Description
An unauthenticated attacker can perform a second-order SQL injection by submitting a crafted referrer URL to the 'wmcTrack' tracking endpoint. The application fails to properly escape the
fullRef parameter and lacks sufficient preparation of the SQL query, allowing the raw value to be stored in the wp logVisit table. The injection is triggered when an administrator views the Traffic Sources dashboard, enabling the extraction of sensitive information from the database.Recommendations
Update WP Visitor Statistics (Real Time Traffic) to version 8.8 or later.
As a temporary mitigation, restrict access to the Traffic Sources dashboard for administrative users until the update is applied.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Visitor Statistics