Sceawere

Vulnerability Detail

CVE-2026-93367UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS in Visitors Traffic

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
19h ago
Vendor
wp-buy
Product
Visitor Traffic Real Time Statistics pro
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-02T04:18:09.573Z",
  "pubdate": "2026-10-02T04:18:09.573Z",
  "executiveSummary": "The Visitors Traffic Real Time Statistics Pro plugin for WordPress is susceptible to an unauthenticated stored Cross-Site Scripting (XSS) vulnerability. This flaw resides in the handling of the 'page_title' parameter during an AJAX request, allowing remote, unauthenticated attackers to inject malicious JavaScript payloads into the plugin's database.\nThe vulnerability is triggered when a WordPress administrator accesses the plugin's dashboard, causing the stored payload to be rendered within the context of the administrator's session. Successful exploitation facilitates the execution of arbitrary scripts, which may result in unauthorized administrative actions, session hijacking, or site-wide compromise.\nAffected versions include all iterations up to and including 11.22. Given that the AJAX action 'ahcpro_track_visitor' is explicitly registered for unauthenticated users, the attack surface is exposed to any remote actor without requiring valid credentials or high-level privileges. Organizations utilizing this plugin are at high risk, as the exploitation is automated, persistent, and bypasses traditional perimeter defenses that do not inspect incoming AJAX POST requests for malicious script tags.\nImmediate remediation is required to sanitize all inputs stored by the plugin and implement secure output encoding within the administrative dashboard.",
  "technicalDetails": "The vulnerability is a classic Stored XSS arising from a failure to perform input sanitization and output escaping within the Visitors Traffic Real Time Statistics Pro plugin. The root cause is the insecure implementation of the 'ahcpro_track_visitor' AJAX action, which is registered via both 'wp_ajax_ahcpro_track_visitor' and the unauthenticated-accessible 'wp_ajax_nopriv_ahcpro_track_visitor' hooks.\nWhen an attacker sends a POST request to the 'ahcpro_track_visitor' action, the plugin processes the 'page_title' parameter directly from the superglobal $_POST array. This raw, unsanitized input is then persisted directly into the database within the 'ahc_title_traffic' table, specifically under the 'til_page_title' column. The plugin fails to apply any validation or sanitization routines, such as 'sanitize_text_field()' or 'esc_html()', prior to the database insertion, allowing for the injection of arbitrary HTML and script tags.\nThe attack flow proceeds as follows: First, the remote, unauthenticated attacker crafts an HTTP POST request containing a malicious JavaScript payload disguised as a legitimate page title within the 'page_title' parameter. Second, the server-side code receives this payload and writes it to the 'til_page_title' column in the 'ahc_title_traffic' database table. Third, the vulnerability remains dormant until a privileged user, typically a WordPress administrator, navigates to the plugin's dashboard interface. Finally, when the dashboard attempts to populate the 'Traffic by Title' DataTable, it retrieves the malicious record and renders the content directly into the DOM using 'innerHTML'.\nBecause the payload is injected into the administrator's dashboard context, the script executes with the privileges of the authenticated administrator. This permits the attacker to perform highly sensitive operations, including the creation of new administrator accounts, the modification of plugin configurations, or the redirection of site traffic to malicious external domains. Furthermore, the attacker can leverage the admin's session to exfiltrate sensitive site data or inject additional persistent backdoors elsewhere within the WordPress environment. The lack of output encoding means that the browser interprets the injected tags as executable code rather than plain text, rendering the mitigation of this threat impossible without intervention in the plugin's source code or the application of robust Web Application Firewall (WAF) rules to filter specific malicious patterns."
}
CVE-2026-93367: Stored XSS in Visitors Traffic (HIGH Severity, CVSS: 7.2) | Sceawere