wp-buy has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 7.2 (high).
CVEs per month
Last 12 months, by publish date
1125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/091026/10
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Weakness classes
Products
- Visitor Traffic Real Time Statistics 1
- Visitor Traffic Real Time Statistics pro 1
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-97341High· 7.2The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header in all versions up to, and including, 8.16 due to insufficient input sanitization and output…40CVE-2026-93367High· 7.2The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX act…40
wp-buy vulnerabilities
CVEs affecting wp-buy, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-97341High· 7.2The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header in all versions up to, and including, 8.16 due to insufficient input sanitization and output…
The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'X-Real-IP' HTTP Header in all versions up to, and including, 8.16 due to insufficient input sanitization and output…
▾ Twilightwp-buy · Visitor Traffic Real Time Statisticsvia NVD
CVE-2026-93367High· 7.2The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX act…
The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX act…
▾ Twilightwp-buy · Visitor Traffic Real Time Statistics proEPSS 0.19%via NVD