CVE-2026-93367: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in wp-buy Visitor Traffic Real Time Statistics pro
The Visitor Traffic Real Time Statistics Pro WordPress plugin contains a stored cross-site scripting (XSS) vulnerability in all versions up to and including 11.22. An unauthenticated attacker can exploit this by submitting malicious JavaScript via the page_title parameter in an AJAX action. This script is stored without sanitization and later executed in an administrator's browser when viewing the plugin dashboard, potentially compromising the admin session.
AI Analysis
Technical Summary
CVE-2026-93367 describes a stored cross-site scripting vulnerability in the Visitor Traffic Real Time Statistics Pro plugin for WordPress, affecting all versions up to 11.22. The vulnerability arises because the plugin's ahcpro_track_visitor AJAX action (accessible to unauthenticated users) stores the page_title POST parameter without sanitization. When an administrator views the 'Traffic by Title' DataTable in the plugin dashboard, the stored page_title is rendered as innerHTML without escaping, allowing arbitrary JavaScript execution in the admin context.
Potential Impact
This vulnerability allows unauthenticated attackers to inject malicious scripts that execute in the context of an administrator's session. This can lead to session hijacking, unauthorized actions performed with admin privileges, and potential compromise of the WordPress site.
Mitigation Recommendations
No patch or official fix is currently confirmed for this vulnerability. Users should check the vendor advisory for updates. Until a fix is available, restrict access to the plugin dashboard to trusted administrators only and consider disabling or removing the plugin if possible to prevent exploitation.
CVE-2026-93367: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in wp-buy Visitor Traffic Real Time Statistics pro
Description
The Visitor Traffic Real Time Statistics Pro WordPress plugin contains a stored cross-site scripting (XSS) vulnerability in all versions up to and including 11.22. An unauthenticated attacker can exploit this by submitting malicious JavaScript via the page_title parameter in an AJAX action. This script is stored without sanitization and later executed in an administrator's browser when viewing the plugin dashboard, potentially compromising the admin session.
CVSS v3.1
Score 7.2high
Affected software
wp-buy
Visitor Traffic Real Time Statistics pro
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93367 describes a stored cross-site scripting vulnerability in the Visitor Traffic Real Time Statistics Pro plugin for WordPress, affecting all versions up to 11.22. The vulnerability arises because the plugin's ahcpro_track_visitor AJAX action (accessible to unauthenticated users) stores the page_title POST parameter without sanitization. When an administrator views the 'Traffic by Title' DataTable in the plugin dashboard, the stored page_title is rendered as innerHTML without escaping, allowing arbitrary JavaScript execution in the admin context.
Potential Impact
This vulnerability allows unauthenticated attackers to inject malicious scripts that execute in the context of an administrator's session. This can lead to session hijacking, unauthorized actions performed with admin privileges, and potential compromise of the WordPress site.
Mitigation Recommendations
No patch or official fix is currently confirmed for this vulnerability. Users should check the vendor advisory for updates. Until a fix is available, restrict access to the plugin dashboard to trusted administrators only and consider disabling or removing the plugin if possible to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-09-17T18:58:09.010Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abf291ca43b0b3b89651cc9
Added to database: 10/02/2026, 03:46:36 UTC
Last enriched: 10/02/2026, 04:01:03 UTC
Last updated: 10/02/2026, 04:05:58 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.