Second-Order SQL Injection in WP Visitor Statistics Plugin
The WP Visitor Statistics plugin (up to 8.7) is vulnerable to a second-order SQL injection allowing unauthenticated attackers to exfiltrate database information via the 'fullRef' parameter.
CVE search metadata
CVE search record: CVE-2026-96267. Severity: high. CVSS: 7.5. KEV: no. Product: WP Visitor Statistics (Real Time Traffic) (<= 8.7). Brief: Second-Order SQL Injection in WP Visitor Statistics Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wp-visitor-statistics-sqli/
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress, in all versions up to and including 8.7, contains a second-order SQL injection vulnerability. The flaw exists due to insufficient input validation and parameter escaping on the 'fullRef' parameter handled by the plugin's tracking endpoint. An unauthenticated attacker can submit a malicious referrer URL to the 'wmcTrack' endpoint, which the plugin stores in the 'wp_logVisit' database table without sanitization. The malicious payload is subsequently executed when an administrator logs in and accesses the 'Traffic Sources' dashboard. This vulnerability allows for potential unauthorized data extraction from the WordPress database. Defenders should monitor web server logs for suspicious requests to the tracking endpoint containing SQL syntax characters.
Attack Chain
- Attacker identifies a target running WP Visitor Statistics (Real Time Traffic) <= 8.7.
- Attacker crafts a malicious HTTP GET or POST request targeting the 'wmcTrack' tracking endpoint.
- Attacker injects a SQL payload into the 'fullRef' parameter value.
- The plugin accepts the input and persists the unescaped malicious string into the 'wp_logVisit' table.
- The attacker waits for an administrator with sufficient privileges to access the WordPress backend.
- The administrator navigates to the 'Traffic Sources' dashboard.
- The application retrieves the poisoned data from 'wp_logVisit' and executes the malicious SQL query.
- The injected query executes, potentially exfiltrating sensitive data from the database.
Impact
Successful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary SQL queries against the WordPress database when an administrator views the plugin's traffic dashboard. This may result in the exfiltration of sensitive configuration data, user credentials, or other stored content within the database.
Recommendation
Update the WP Visitor Statistics (Real Time Traffic) plugin to the latest version once a patch is available. Until a patch is applied, disable the plugin to prevent unauthenticated data injection. Configure Web Application Firewalls (WAF) to inspect the 'fullRef' parameter for common SQL injection patterns.
Detection
Detect malicious tracking requests by inspecting web access logs for characters typically associated with SQL injection (e.g., single quotes, semicolons, comments) within the query string or body targeted at the tracking endpoint.
Immediate actions
Audit web logs for requests targeting 'wmcTrack' containing suspicious characters.
Mitigations
Disable or update the WP Visitor Statistics plugin to a patched version.
CVE-2026-96267
Detection coverage 1
Detect CVE-2026-96267 Exploitation - SQL Injection in wmcTrack Endpoint
highDetects potential SQL injection attempts against the WP Visitor Statistics plugin by monitoring the wmcTrack endpoint for common SQL metacharacters.
Detection queries are available on the platform. Get full rules →