---
id: CVE-2026-93367
title: >-
  The Visitors Traffic Real Time Statistics Pro plugin for WordPress is
  vulnerable to unauthenticated stored Cross-Site Scripting in all versions up
  to, and including, 11.22 via the page_title parameter of the
  ahcpro_track_visitor AJAX act…
summary: >-
  The Visitors Traffic Real Time Statistics Pro plugin for WordPress is
  vulnerable to unauthenticated stored Cross-Site Scripting in all versions up
  to, and including, 11.22 via the page_title parameter of the
  ahcpro_track_visitor AJAX act…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: wp-buy
product: Visitor Traffic Real Time Statistics pro
affected:
  - visitor_traffic_real_time_statistics_pro <= 11.22
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T20:17:04.933'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93367'
references:
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/a72261e5-7376-4a34-9264-27bd4f27e938?source=cve
    label: security@wordfence.com
  - url: 'https://www.wp-buy.com/product/visitors-traffic-real-time-statistics-pro/'
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-02T19:53:08.942409Z'
epss: 0.00194
epssPercentile: 0.08207
ingestedAt: '2026-10-02T04:09:34.547Z'
---

## Overview

The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is registered for logged-out callers (wp_ajax_nopriv_ahcpro_track_visitor) and stores $_POST['page_title'] with NO sanitization, keeping it raw in the ahc_title_traffic.til_page_title column. When an administrator opens the plugin's dashboard, the 'Traffic by Title' DataTable renders that stored value as innerHTML without output escaping, executing arbitrary JavaScript. This makes it possible for unauthenticated attackers to inject web scripts that run in an administrator's session.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
