PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-2936 wp-buy CVE debrief

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an admin user accesses the Traffic by Title section. Affected product scope includes WordPress sites using the Visitor Traffic Real Time Statistics plugin. The vulnerability has a high CVSS score of 7.2, indicating high severity.

Vendor
wp-buy
Product
Visitor Traffic Real Time Statistics
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-04
Original CVE updated
2026-07-24
Advisory published
2026-04-04
Advisory updated
2026-07-24

Who should care

Administrators and users of WordPress sites using the Visitor Traffic Real Time Statistics plugin, especially those with high-traffic sites or sensitive data, should prioritize patching this vulnerability. Security teams should review the official advisory and CVE record to validate affected scope and severity. Vulnerability management and security teams should track exceptions and retest remediated assets.

Technical summary

The CVE-2026-2936 vulnerability is caused by insufficient input sanitization and output escaping in the 'page_title' parameter of the Visitor Traffic Real Time Statistics plugin for WordPress. This allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an admin user accesses the Traffic by Title section. The vulnerability has a high CVSS score of 7.2, indicating high severity. Defenders should focus on updating the plugin and implementing input validation and output encoding.

Defensive priority

High priority due to the high CVSS score of 7.2 and the potential for unauthenticated attacks.

Recommended defensive actions

  • Update the Visitor Traffic Real Time Statistics plugin to the latest version.
  • Implement input validation and output encoding for user-supplied data.
  • Monitor for suspicious activity and implement a Web Application Firewall (WAF) to detect and prevent attacks.
  • Regularly review and update plugins and themes to ensure they are compatible and secure.
  • Consider implementing a security scanner to identify potential vulnerabilities.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record was published on 2026-04-04T12:16:03.090Z and last modified on 2026-07-24T22:10:00.140Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD details. Defenders should verify affected product deployments and review official advisories.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-2936 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-2936

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-2936 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-2936

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.