<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WP Visitor Statistics (Real Time Traffic) (&lt;= 8.7) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wp-visitor-statistics-real-time-traffic--8.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 03 Oct 2026 08:54:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wp-visitor-statistics-real-time-traffic--8.7/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Second-Order SQL Injection in WP Visitor Statistics Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-wp-visitor-statistics-sqli/</link><pubDate>Sat, 03 Oct 2026 08:54:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-wp-visitor-statistics-sqli/</guid><description>The WP Visitor Statistics plugin (up to 8.7) is vulnerable to a second-order SQL injection allowing unauthenticated attackers to exfiltrate database information via the 'fullRef' parameter.</description><content:encoded><![CDATA[<p>The WP Visitor Statistics (Real Time Traffic) plugin for WordPress, in all versions up to and including 8.7, contains a second-order SQL injection vulnerability. The flaw exists due to insufficient input validation and parameter escaping on the 'fullRef' parameter handled by the plugin's tracking endpoint. An unauthenticated attacker can submit a malicious referrer URL to the 'wmcTrack' endpoint, which the plugin stores in the 'wp_logVisit' database table without sanitization. The malicious payload is subsequently executed when an administrator logs in and accesses the 'Traffic Sources' dashboard. This vulnerability allows for potential unauthorized data extraction from the WordPress database. Defenders should monitor web server logs for suspicious requests to the tracking endpoint containing SQL syntax characters.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target running WP Visitor Statistics (Real Time Traffic) &lt;= 8.7.</li>
<li>Attacker crafts a malicious HTTP GET or POST request targeting the 'wmcTrack' tracking endpoint.</li>
<li>Attacker injects a SQL payload into the 'fullRef' parameter value.</li>
<li>The plugin accepts the input and persists the unescaped malicious string into the 'wp_logVisit' table.</li>
<li>The attacker waits for an administrator with sufficient privileges to access the WordPress backend.</li>
<li>The administrator navigates to the 'Traffic Sources' dashboard.</li>
<li>The application retrieves the poisoned data from 'wp_logVisit' and executes the malicious SQL query.</li>
<li>The injected query executes, potentially exfiltrating sensitive data from the database.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated attackers to execute arbitrary SQL queries against the WordPress database when an administrator views the plugin's traffic dashboard. This may result in the exfiltration of sensitive configuration data, user credentials, or other stored content within the database.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the WP Visitor Statistics (Real Time Traffic) plugin to the latest version once a patch is available. Until a patch is applied, disable the plugin to prevent unauthenticated data injection. Configure Web Application Firewalls (WAF) to inspect the 'fullRef' parameter for common SQL injection patterns.</p>
<h2 id="detection">Detection</h2>
<p>Detect malicious tracking requests by inspecting web access logs for characters typically associated with SQL injection (e.g., single quotes, semicolons, comments) within the query string or body targeted at the tracking endpoint.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>sqli</category><category>web-application</category><category>wordpress</category></item></channel></rss>