Unauthenticated Stored XSS in Visitors Traffic Real Time Statistics Pro
The Visitors Traffic Real Time Statistics Pro WordPress plugin contains an unauthenticated stored XSS vulnerability allowing remote attackers to execute arbitrary JavaScript in the context of an administrator's browser.
CVE search metadata
CVE search record: CVE-2026-93367. Severity: high. CVSS: 7.2. KEV: no. Product: Visitors Traffic Real Time Statistics Pro (<= 11.22). Brief: Unauthenticated Stored XSS in Visitors Traffic Real Time Statistics Pro. Brief link: https://feed.craftedsignal.io/briefs/2026-10-02-cve-2026-93367/
Visitors Traffic Real Time Statistics Pro (versions up to and including 11.22) is affected by a stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2026-93367. The vulnerability exists within the 'ahcpro_track_visitor' AJAX action, which is explicitly registered for unauthenticated users via 'wp_ajax_nopriv_ahcpro_track_visitor'. The plugin fails to sanitize the 'page_title' POST parameter before storing it in the database column 'ahc_title_traffic.til_page_title'. When an administrator accesses the plugin's 'Traffic by Title' dashboard, the stored value is rendered as innerHTML without appropriate output escaping. This flaw allows an unauthenticated attacker to inject malicious JavaScript payloads that execute with the privileges of the administrator's session, potentially leading to unauthorized configuration changes, account takeover, or administrative actions within the WordPress environment.
Impact
Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator's session. This may result in the full compromise of the WordPress site if the administrator is tricked into visiting the affected plugin dashboard. Impact includes unauthorized creation of administrative users, modification of site content, or redirection of site traffic.
Recommendation
Update the Visitors Traffic Real Time Statistics Pro plugin to the latest available version (beyond 11.22) that includes sanitization for the 'page_title' parameter. If an update is not immediately available, disable the plugin or restrict access to the dashboard until a patch is applied.
Immediate actions
Upgrade Visitors Traffic Real Time Statistics Pro to latest version
Mitigations
Upgrade to latest version beyond 11.22
CVE-2026-93367
Detection coverage 1
Detect CVE-2026-93367 - Unauthenticated XSS Injection Attempt
highDetects exploitation attempts against CVE-2026-93367 by monitoring for HTTP POST requests to the ahcpro_track_visitor AJAX action containing script tags or event handlers in the page_title parameter.
Detection queries are available on the platform. Get full rules →