CVE-2026-93367

CVE-2026-93367 published: The Visitors Traffic Real Time Statistics Pro plugin for WordPress is vulnerable to unauthenticated stored Cross-Site Scripting in all versions up to, and including, 11.22 via the page_title parameter of the ahcpro_track_visitor AJAX action. The action is r...

View full NVD advisory → ← Back to CVE watch