<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Visitors Traffic Real Time Statistics Pro (&lt;= 11.22) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/visitors-traffic-real-time-statistics-pro--11.22/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 04:22:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/visitors-traffic-real-time-statistics-pro--11.22/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Stored XSS in Visitors Traffic Real Time Statistics Pro</title><link>https://feed.craftedsignal.io/briefs/2026-10-02-cve-2026-93367/</link><pubDate>Fri, 02 Oct 2026 04:22:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-02-cve-2026-93367/</guid><description>The Visitors Traffic Real Time Statistics Pro WordPress plugin contains an unauthenticated stored XSS vulnerability allowing remote attackers to execute arbitrary JavaScript in the context of an administrator's browser.</description><content:encoded><![CDATA[<p>Visitors Traffic Real Time Statistics Pro (versions up to and including 11.22) is affected by a stored Cross-Site Scripting (XSS) vulnerability, identified as CVE-2026-93367. The vulnerability exists within the 'ahcpro_track_visitor' AJAX action, which is explicitly registered for unauthenticated users via 'wp_ajax_nopriv_ahcpro_track_visitor'. The plugin fails to sanitize the 'page_title' POST parameter before storing it in the database column 'ahc_title_traffic.til_page_title'. When an administrator accesses the plugin's 'Traffic by Title' dashboard, the stored value is rendered as innerHTML without appropriate output escaping. This flaw allows an unauthenticated attacker to inject malicious JavaScript payloads that execute with the privileges of the administrator's session, potentially leading to unauthorized configuration changes, account takeover, or administrative actions within the WordPress environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of an administrator's session. This may result in the full compromise of the WordPress site if the administrator is tricked into visiting the affected plugin dashboard. Impact includes unauthorized creation of administrative users, modification of site content, or redirection of site traffic.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the Visitors Traffic Real Time Statistics Pro plugin to the latest available version (beyond 11.22) that includes sanitization for the 'page_title' parameter. If an update is not immediately available, disable the plugin or restrict access to the dashboard until a patch is applied.</p>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>web-vulnerability</category><category>xss</category><category>wordpress</category></item></channel></rss>