OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-93367

HIGH · CVSS 7.2 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting due to improper handling of the page_title parameter in the ahcpro_track_visitor AJAX action, allowing attackers to inject malicious scripts. The impact is significant, as these scripts can execute in the context of an administrator's session when the dashboard is accessed, potentially leading to unauthorized actions or data exposure. WordPress site administrators using this plugin should prioritize patching or mitigating this vulnerability to protect against potential exploitation.

CVE
CVE-2026-93367
Severity
HIGH
CVSS
7.2
EPSS
0.19%
WordPress Java

Original NVD Description

The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session.