Description
The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection: an unauthenticated attacker submits a crafted referrer URL to the wmcTrack tracking endpoint, which persists the raw unescaped value into the wp_logVisit table, and the injection is triggered when an administrator next views the Traffic Sources dashboard.
Published: 2026-10-03
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated SQL Injection
Action: Immediate Patch
AI Analysis

Impact

The WP Visitor Statistics (Real Time Traffic) plugin contains a second‑order SQL injection flaw in the 'fullRef' parameter. An unauthenticated attacker can inject crafted SQL through a referrer URL that is stored in the wp_logVisit table, and the injection is triggered the next time an administrator views the Traffic Sources dashboard. This allows the attacker to read sensitive information from the WordPress database, such as user data or site configuration, but does not provide code execution or immediate denial of service.

Affected Systems

WordPress sites running the WP Visitor Statistics (Real Time Traffic) plugin by osamaesh, versions 8.7 and earlier, are affected. Any WordPress installation that has not applied a patch that removes the unescaped 'fullRef' parameter in these plugin versions is vulnerable.

Risk and Exploitability

The CVSS score for this vulnerability is 7.5, indicating a high risk to confidentiality. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated access: a malicious actor can craft a referrer URL and host it, after which a site administrator's visit to the Traffic Sources dashboard will trigger the injected SQL. Because the exploit requires an admin to view the dashboard, an attacker may need to wait for or entice an admin’s interaction, but given the ubiquity of such dashboards, exploitation is feasible and can result in disclosure of sensitive database contents.

Generated by OpenCVE AI on October 3, 2026 at 08:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the WP Visitor Statistics plugin to version 8.8 or newer, which replaces the vulnerable query with prepared statements and proper escaping.
  • If an immediate update is not feasible, block or sanitize the 'fullRef' parameter by adding a server rule that rejects SQL‑like content or by modifying the plugin code to use esc_sql() on the value.
  • Deploy a web application firewall that detects and blocks SQL injection patterns, specifically targeting requests to the wmcTrack endpoint and the Traffic Sources dashboard.
  • Regularly review WordPress and plugin updates to ensure that similar injection vulnerabilities are addressed promptly.

Generated by OpenCVE AI on October 3, 2026 at 08:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection: an unauthenticated attacker submits a crafted referrer URL to the wmcTrack tracking endpoint, which persists the raw unescaped value into the wp_logVisit table, and the injection is triggered when an administrator next views the Traffic Sources dashboard.
Title WP Visitor Statistics (Real Time Traffic) <= 8.7 - Unauthenticated SQL Injection via 'fullRef' Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:41.771Z

Reserved: 2026-09-22T20:25:24.416Z

Link: CVE-2026-96267

cve-icon Vulnrichment

Updated: 2026-10-03T15:38:43.663Z

cve-icon NVD

Status : Received

Published: 2026-10-03T07:16:49.200

Modified: 2026-10-03T16:16:46.693

Link: CVE-2026-96267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T08:30:18Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')