<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Visitor Traffic Real Time Statistics (&lt;= 8.16) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/visitor-traffic-real-time-statistics--8.16/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 06:54:57 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/visitor-traffic-real-time-statistics--8.16/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored DOM-Based XSS in Visitor Traffic Real Time Statistics WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-97341/</link><pubDate>Sat, 03 Oct 2026 06:54:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-97341/</guid><description>An unauthenticated Stored DOM-Based XSS vulnerability in the Visitor Traffic Real Time Statistics plugin allows attackers to inject malicious scripts via the 'X-Real-IP' header.</description><content:encoded><![CDATA[<p>The Visitor Traffic Real Time Statistics plugin for WordPress, in versions 8.16 and earlier, is susceptible to a Stored DOM-Based Cross-Site Scripting (XSS) vulnerability. The flaw exists because the plugin fails to properly sanitize or escape input provided via the 'X-Real-IP' HTTP header before storing it in the WordPress database. This vulnerability is reachable through the 'wp_ajax_nopriv_ahcfree_track_visitor' endpoint, which does not require any authentication, nonces, or administrative capabilities. Consequently, an unauthenticated attacker can supply a crafted JavaScript payload in the 'X-Real-IP' header, which is then persisted in the site database. Whenever an administrator or other user accesses the affected page within the WordPress dashboard or public-facing tracking views, the stored script executes in the victim's browser, potentially leading to session hijacking, unauthorized actions, or further compromise of the WordPress environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of any user viewing the statistics page. This can lead to full compromise of administrative sessions, theft of authentication cookies, or the redirection of site visitors to malicious external sites. The impact is elevated due to the lack of required authentication, allowing wide-scale automated scanning and exploitation of affected WordPress installations globally.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize updating the Visitor Traffic Real Time Statistics plugin to the latest version. Monitor web server access logs for anomalous 'X-Real-IP' header values containing suspicious characters (e.g., &lt;, &gt;, script, alert). Deploy Web Application Firewall (WAF) rules to inspect the 'X-Real-IP' header for web script signatures before the request reaches the WordPress application.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>