{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/visitors-traffic-real-time-statistics-pro--11.22/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:visitors_traffic_real_time_statistics_pro:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-93367"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Visitors Traffic Real Time Statistics Pro (\u003c= 11.22)"],"_cs_severities":["medium"],"_cs_tags":["web-vulnerability","xss","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eVisitors Traffic Real Time Statistics Pro (versions up to and including 11.22) is affected by a stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2026-93367. The vulnerability exists within the 'ahcpro_track_visitor' AJAX action, which is explicitly registered for unauthenticated users via 'wp_ajax_nopriv_ahcpro_track_visitor'. The plugin fails to sanitize the 'page_title' POST parameter before storing it in the database column 'ahc_title_traffic.til_page_title'. When an administrator accesses the plugin's 'Traffic by Title' dashboard, the stored value is rendered as innerHTML without appropriate output escaping. This flaw allows an unauthenticated attacker to inject malicious JavaScript payloads that execute with the privileges of the administrator's session, potentially leading to unauthorized configuration changes, account takeover, or administrative actions within the WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator's session. This may result in the full compromise of the WordPress site if the administrator is tricked into visiting the affected plugin dashboard. Impact includes unauthorized creation of administrative users, modification of site content, or redirection of site traffic.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Visitors Traffic Real Time Statistics Pro plugin to the latest available version (beyond 11.22) that includes sanitization for the 'page_title' parameter. If an update is not immediately available, disable the plugin or restrict access to the dashboard until a patch is applied.\u003c/p\u003e\n","date_modified":"2026-10-02T04:22:28Z","date_published":"2026-10-02T04:22:28Z","id":"https://feed.craftedsignal.io/briefs/2026-10-02-cve-2026-93367/","summary":"The Visitors Traffic Real Time Statistics Pro WordPress plugin contains an unauthenticated stored XSS vulnerability allowing remote attackers to execute arbitrary JavaScript in the context of an administrator's browser.","title":"Unauthenticated Stored XSS in Visitors Traffic Real Time Statistics Pro","url":"https://feed.craftedsignal.io/briefs/2026-10-02-cve-2026-93367/"}],"language":"en","title":"CraftedSignal Threat Feed - Visitors Traffic Real Time Statistics Pro (\u003c= 11.22)","version":"https://jsonfeed.org/version/1.1"}