PT-2026-30345 · WordPress · Visitors-Traffic-Real-Time-Statistics

Supakiad S

·

Published

2026-04-04

·

Updated

2026-04-05

·

CVE-2026-2936

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Visitor Traffic Real Time Statistics plugin for WordPress versions up to and including 8.4
Description The Visitor Traffic Real Time Statistics plugin for WordPress is susceptible to Stored Cross-Site Scripting through the page title parameter. Insufficient input sanitization and output escaping allow unauthenticated attackers to inject arbitrary web scripts into pages. These scripts will execute when an administrator accesses the Traffic by Title section.
Recommendations Update the Visitor Traffic Real Time Statistics plugin to a version later than 8.4.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2936

Affected Products

Visitors-Traffic-Real-Time-Statistics