{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wp-visitor-statistics-real-time-traffic--8.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:wp_visitor_statistics:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-96267"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Visitor Statistics (Real Time Traffic) (\u003c= 8.7)"],"_cs_severities":["high"],"_cs_tags":["sqli","web-application","wordpress"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe WP Visitor Statistics (Real Time Traffic) plugin for WordPress, in all versions up to and including 8.7, contains a second-order SQL injection vulnerability. The flaw exists due to insufficient input validation and parameter escaping on the 'fullRef' parameter handled by the plugin's tracking endpoint. An unauthenticated attacker can submit a malicious referrer URL to the 'wmcTrack' endpoint, which the plugin stores in the 'wp_logVisit' database table without sanitization. The malicious payload is subsequently executed when an administrator logs in and accesses the 'Traffic Sources' dashboard. This vulnerability allows for potential unauthorized data extraction from the WordPress database. Defenders should monitor web server logs for suspicious requests to the tracking endpoint containing SQL syntax characters.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target running WP Visitor Statistics (Real Time Traffic) \u0026lt;= 8.7.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET or POST request targeting the 'wmcTrack' tracking endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker injects a SQL payload into the 'fullRef' parameter value.\u003c/li\u003e\n\u003cli\u003eThe plugin accepts the input and persists the unescaped malicious string into the 'wp_logVisit' table.\u003c/li\u003e\n\u003cli\u003eThe attacker waits for an administrator with sufficient privileges to access the WordPress backend.\u003c/li\u003e\n\u003cli\u003eThe administrator navigates to the 'Traffic Sources' dashboard.\u003c/li\u003e\n\u003cli\u003eThe application retrieves the poisoned data from 'wp_logVisit' and executes the malicious SQL query.\u003c/li\u003e\n\u003cli\u003eThe injected query executes, potentially exfiltrating sensitive data from the database.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary SQL queries against the WordPress database when an administrator views the plugin's traffic dashboard. This may result in the exfiltration of sensitive configuration data, user credentials, or other stored content within the database.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the WP Visitor Statistics (Real Time Traffic) plugin to the latest version once a patch is available. Until a patch is applied, disable the plugin to prevent unauthenticated data injection. Configure Web Application Firewalls (WAF) to inspect the 'fullRef' parameter for common SQL injection patterns.\u003c/p\u003e\n\u003ch2 id=\"detection\"\u003eDetection\u003c/h2\u003e\n\u003cp\u003eDetect malicious tracking requests by inspecting web access logs for characters typically associated with SQL injection (e.g., single quotes, semicolons, comments) within the query string or body targeted at the tracking endpoint.\u003c/p\u003e\n","date_modified":"2026-10-03T08:54:49Z","date_published":"2026-10-03T08:54:49Z","id":"https://feed.craftedsignal.io/briefs/2026-10-wp-visitor-statistics-sqli/","summary":"The WP Visitor Statistics plugin (up to 8.7) is vulnerable to a second-order SQL injection allowing unauthenticated attackers to exfiltrate database information via the 'fullRef' parameter.","title":"Second-Order SQL Injection in WP Visitor Statistics Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-wp-visitor-statistics-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - WP Visitor Statistics (Real Time Traffic) (\u003c= 8.7)","version":"https://jsonfeed.org/version/1.1"}