PT-2026-104549 · WordPress · Wp Visitor Statistics

·

CVE-2026-96267

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Visitor Statistics (Real Time Traffic) versions prior to 8.8
Description An unauthenticated attacker can perform a second-order SQL injection by submitting a crafted referrer URL to the 'wmcTrack' tracking endpoint. The application fails to properly escape the fullRef parameter and lacks sufficient preparation of the SQL query, allowing the raw value to be stored in the wp logVisit table. The injection is triggered when an administrator views the Traffic Sources dashboard, enabling the extraction of sensitive information from the database.
Recommendations Update WP Visitor Statistics (Real Time Traffic) to version 8.8 or later. As a temporary mitigation, restrict access to the Traffic Sources dashboard for administrative users until the update is applied.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96267

Affected Products

Wp Visitor Statistics