Impact
The Visitor Traffic Real Time Statistics plugin has a stored DOM‑based XSS flaw that accepts an unsanitized X‑Real‑IP header. The plugin records the header's entity‑encoded payload directly into its database through the wp_ajax_nopriv_ahcfree_track_visitor endpoint. An attacker can therefore inject a script that will be executed in the browsers of any subsequent user who visits a page that renders the stored data. This can lead to data theft, session hijack, or defacement.
Affected Systems
WordPress sites that have installed the Visitor Traffic Real Time Statistics plugin from wp‑buy, in any release up to and including version 8.16. All copies of the plugin bundled with releases through 8.16 are vulnerable because the same code path is present across those versions.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity; the flaw requires no authentication, nonce or capability and can be abused using only a forged HTTP header. Because the endpoint accepts any request, exploitation is straightforward. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, but the ease of use and potential damage make it a serious risk for any affected WordPress installation.
OpenCVE Enrichment