Junglewise Threat Intelligence

CVE-2026-90986: Visitor Traffic Real Time Statistics Pro Unauthenticated XSS

CVE-2026-90986 · Severity: high · CVSS 7.1 · Published 2026-09-17

Executive brief

Visitor Traffic Real Time Statistics Pro is a WordPress plugin that tracks and displays visitor statistics on websites. An unauthenticated attacker can inject malicious scripts into the site through this plugin, allowing them to steal visitor data, hijack user accounts, or deface content without requiring any special access.

Technical details

This is a Cross Site Scripting (XSS) vulnerability classified as injection attack (OWASP A3). The vulnerability exists in Visitor Traffic Real Time Statistics Pro plugin versions up to and including 11.21, allowing unauthenticated attackers to inject malicious scripts. While the vulnerability can be initiated by any user, successful exploitation requires a privileged user (such as an admin) to perform an action like clicking a malicious link or visiting a crafted page. The vulnerability has been patched in version 11.22 and later.

Affected products

  • Visitor Traffic Real Time Statistics Pro Visitor Traffic Real Time Statistics Pro <=11.21

Timeline

  • 2026-09-17: disclosed
  • 2026-08-03: other: Reported by Nguyen Ba Khanh - HPT Vietnam Corporation

References