CVE-2026-96267 Overview
The WP Visitor Statistics (Real Time Traffic) WordPress plugin contains a second-order SQL Injection vulnerability affecting all versions up to and including 8.7. The flaw resides in the handling of the fullRef parameter sent to the wmcTrack tracking endpoint. Insufficient escaping of user-supplied input and lack of prepared statements allow unauthenticated attackers to persist malicious payloads to the wp_logVisit table. The injection executes when an administrator later views the Traffic Sources dashboard, enabling extraction of sensitive data from the WordPress database.
Critical Impact
Unauthenticated attackers can inject arbitrary SQL that executes in an authenticated administrator context, exposing database contents including credentials and session data.
Affected Products
- WP Visitor Statistics (Real Time Traffic) plugin for WordPress, versions up to and including 8.7
- WordPress sites using the wp-stats-manager plugin with the wmcTrack endpoint exposed
- WordPress installations where administrators access the Traffic Sources dashboard
Discovery Timeline
- 2026-10-03 - CVE-2026-96267 published to NVD
- 2026-10-06 - Last updated in NVD database
Technical Details for CVE-2026-96267
Vulnerability Analysis
The vulnerability is a classic second-order SQL Injection [CWE-89]. In a first-order injection, the attacker's payload executes in the same request that submits it. In a second-order injection, the payload is stored first and executed in a later, separate database operation. This distinction matters because many web application firewalls focus on request-time inspection and may miss payloads that only become dangerous during administrative review.
An unauthenticated attacker sends a crafted HTTP request to the wmcTrack tracking endpoint with a malicious fullRef referrer value. The plugin writes this raw value into the wp_logVisit table without escaping or parameterization. When an administrator later opens the Traffic Sources dashboard, the plugin reads the stored value and concatenates it into a new SQL query. The database engine then parses the attacker-controlled fragment as SQL syntax.
Root Cause
The plugin treats referrer data as safe once it is stored, violating the principle that all database input must be parameterized at the point of query construction. The dashboard rendering code builds queries using string concatenation against values retrieved from wp_logVisit, rather than using WordPress $wpdb->prepare() with placeholders.
Attack Vector
The attack requires no authentication and no user interaction from the attacker's perspective. The attacker submits a single HTTP request containing a crafted referrer header or parameter. Exploitation triggers once any administrator reviews the Traffic Sources report. Technical details on the vulnerable code paths are documented in the WordPress Plugin Code Snippet and the Wordfence Vulnerability Analysis.
Detection Methods for CVE-2026-96267
Indicators of Compromise
- Entries in wp_logVisit where the referrer field contains SQL metacharacters such as single quotes, UNION, SELECT, SLEEP(, or comment sequences -- and /*
- HTTP requests to admin-ajax.php or wmcTrack endpoints with abnormally long or encoded fullRef parameter values
- Unexpected read errors or long query durations when administrators load the Traffic Sources dashboard
Detection Strategies
- Inspect WordPress access logs for POST or GET requests targeting the plugin's tracking endpoint with suspicious referrer payloads
- Query the wp_logVisit table directly for rows containing SQL syntax before administrators open the dashboard
- Enable MySQL general query logging on staging systems to identify concatenated queries referencing stored referrer values
Monitoring Recommendations
- Alert on any database error returned from the plugin's statistics queries, which often indicate injection probing
- Monitor administrator session activity after dashboard access for unexpected privilege changes or data export operations
- Track outbound connections from the web server that correlate with administrator dashboard views, which may indicate out-of-band data exfiltration
How to Mitigate CVE-2026-96267
Immediate Actions Required
- Update the WP Visitor Statistics plugin to a version later than 8.7 as soon as the vendor publishes a fix
- Audit the wp_logVisit table and purge rows containing SQL metacharacters in the referrer field before administrators access the dashboard
- Restrict administrative access to the Traffic Sources dashboard until the plugin is patched
Patch Information
The plugin repository commit is tracked in the WordPress Change Set. Administrators should apply the vendor-released update through the WordPress plugin management interface and verify the installed version is above 8.7 before restoring normal operations.
Workarounds
- Deactivate the WP Visitor Statistics plugin until a patched version is installed
- Deploy a web application firewall rule blocking requests to wmcTrack endpoints that contain SQL keywords in referrer parameters
- Revoke write access to the wp_logVisit table from the web application database user if plugin functionality is not required
# Configuration example
wp plugin deactivate wp-stats-manager
wp db query "DELETE FROM wp_logVisit WHERE referer REGEXP '(UNION|SELECT|SLEEP|--|/\*)';"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.