Skip to content
Threat Feed
high advisory

Second-Order SQL Injection in WP Visitor Statistics Plugin

The WP Visitor Statistics plugin (up to 8.7) is vulnerable to a second-order SQL injection allowing unauthenticated attackers to exfiltrate database information via the 'fullRef' parameter.

CVE search metadata

CVE search record: CVE-2026-96267. Severity: high. CVSS: 7.5. KEV: no. Product: WP Visitor Statistics (Real Time Traffic) (<= 8.7). Brief: Second-Order SQL Injection in WP Visitor Statistics Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-wp-visitor-statistics-sqli/

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress, in all versions up to and including 8.7, contains a second-order SQL injection vulnerability. The flaw exists due to insufficient input validation and parameter escaping on the 'fullRef' parameter handled by the plugin's tracking endpoint. An unauthenticated attacker can submit a malicious referrer URL to the 'wmcTrack' endpoint, which the plugin stores in the 'wp_logVisit' database table without sanitization. The malicious payload is subsequently executed when an administrator logs in and accesses the 'Traffic Sources' dashboard. This vulnerability allows for potential unauthorized data extraction from the WordPress database. Defenders should monitor web server logs for suspicious requests to the tracking endpoint containing SQL syntax characters.

Attack Chain

  1. Attacker identifies a target running WP Visitor Statistics (Real Time Traffic) <= 8.7.
  2. Attacker crafts a malicious HTTP GET or POST request targeting the 'wmcTrack' tracking endpoint.
  3. Attacker injects a SQL payload into the 'fullRef' parameter value.
  4. The plugin accepts the input and persists the unescaped malicious string into the 'wp_logVisit' table.
  5. The attacker waits for an administrator with sufficient privileges to access the WordPress backend.
  6. The administrator navigates to the 'Traffic Sources' dashboard.
  7. The application retrieves the poisoned data from 'wp_logVisit' and executes the malicious SQL query.
  8. The injected query executes, potentially exfiltrating sensitive data from the database.

Impact

Successful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary SQL queries against the WordPress database when an administrator views the plugin's traffic dashboard. This may result in the exfiltration of sensitive configuration data, user credentials, or other stored content within the database.

Recommendation

Update the WP Visitor Statistics (Real Time Traffic) plugin to the latest version once a patch is available. Until a patch is applied, disable the plugin to prevent unauthenticated data injection. Configure Web Application Firewalls (WAF) to inspect the 'fullRef' parameter for common SQL injection patterns.

Detection

Detect malicious tracking requests by inspecting web access logs for characters typically associated with SQL injection (e.g., single quotes, semicolons, comments) within the query string or body targeted at the tracking endpoint.


Immediate actions

Audit web logs for requests targeting 'wmcTrack' containing suspicious characters.

SOC 24h

Mitigations

Disable or update the WP Visitor Statistics plugin to a patched version.

immediate IT Operations

CVE-2026-96267

Detection coverage 1

Detect CVE-2026-96267 Exploitation - SQL Injection in wmcTrack Endpoint

high

Detects potential SQL injection attempts against the WP Visitor Statistics plugin by monitoring the wmcTrack endpoint for common SQL metacharacters.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →