PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-96267 osamaesh CVE debrief

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7. This vulnerability allows unauthenticated attackers to append additional SQL queries into existing queries, potentially leading to sensitive information extraction from the database. The injection occurs when an administrator views the Traffic Sources dashboard after an attacker submits a crafted referrer URL to the wmcTrack tracking endpoint.

Vendor
osamaesh
Product
WP Visitor Statistics (Real Time Traffic)
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-03
Original CVE updated
2026-10-03
Advisory published
2026-10-03
Advisory updated
2026-10-03

Who should care

WordPress administrators and users of the WP Visitor Statistics plugin should assess their exposure and take necessary actions to mitigate the vulnerability. This includes reviewing plugin versions, applying patches, and implementing additional security measures to prevent exploitation. The vulnerability's impact on the organization depends on the sensitivity of the data stored in the database and the potential for unauthorized access or disruption of Word

Why it matters

CVE-2026-96267 is a high-severity SQL injection vulnerability in the WP Visitor Statistics plugin for WordPress. It allows unauthenticated attackers to potentially extract sensitive information from the database. WordPress administrators and users of the affected plugin should assess their exposure and apply necessary patches or mitigations as soon as possible.

  • Potential extraction of sensitive information from the database by unauthenticated attackers.
  • Possible disruption of service due to unauthorized database queries.
  • Need for verification of plugin version and exposure.
  • Requirement for patching or mitigation to prevent exploitation.

Technical summary

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the 'fullRef' parameter in all versions up to, and including, 8.7. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. The vulnerability is a second-order SQL injection, where an unauthenticated attacker submits a crafted referrer URL to the wmcTrack tracking endpoint, which persists the raw unescaped value into the wp_logVisit table. The injection is triggered when an administrator next views the Traffic Sources dashboard.

Defensive priority

High priority for WordPress administrators and users of the WP Visitor Statistics plugin to assess exposure and apply necessary patches or mitigations.

Recommended defensive actions

  • Assess exposure by checking if the WP Visitor Statistics plugin version is 8.7 or earlier.
  • Apply patches or updates provided by the plugin vendor as soon as they are available.
  • Implement additional monitoring and logging to detect potential SQL injection attempts.
  • Review and restrict access to the Traffic Sources dashboard to minimize exposure.
  • Perform a thorough review of database logs to identify any potential malicious activity.
  • Consider implementing a web application firewall (WAF) to detect and prevent SQL injection attacks.
  • Conduct a security audit of the plugin and its configuration to identify any other potential vulnerabilities.

Evidence notes

The vulnerability is confirmed in versions up to and including 8.7 of the WP Visitor Statistics plugin. The attack vector involves submitting a crafted referrer URL to the wmcTrack endpoint, which stores the raw value in the wp_logVisit table. The SQL injection is triggered when an administrator views the Traffic Sources dashboard.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-96267 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-96267

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-96267 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96267

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.