CVE-2026-97341 | Visitor Traffic Real Time Statistics Plugin up to 8.16 on WordPress wp_ajax_nopriv_ahcfree_track_visitor X-Real-IP cross site scripting

SecurityVulns

A vulnerability marked as problematic has been reported in Visitor Traffic Real Time Statistics Plugin up to 8.16 on WordPress. Affected is the function wp_ajax_nopriv_ahcfree_track_visitor. The manipulation of the argument X-Real-IP leads to cross site scripting.

This vulnerability is documented as CVE-2026-97341. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More