天下漏洞,尽知其名
HIGH 重点关注

CVE-2026-96267 WordPress WP Visitor Statistics 二阶 SQL 注入漏洞

影响未授权攻击者可注入 SQL 读取数据库敏感信息

AI 研判

WordPress 插件 WP Visitor Statistics (Real Time Traffic) 存在二阶 SQL 注入漏洞。未授权攻击者向 wmcTrack 跟踪端点提交恶意 referrer URL,原始未转义的值被写入 wp_logVisit 表,当管理员查看流量来源仪表盘时触发注入。

影响范围

WP Visitor Statistics (Real Time Traffic)

所有版本至 8.7(含 8.7)均受影响,暂无公开的已修复版本信息。

漏洞详情

漏洞类型为二阶 SQL 注入,成因是插件对用户可控的 'fullRef' 参数转义不足,且构造 SQL 查询时未使用预处理语句。攻击者先将恶意 SQL 片段通过跟踪接口持久化到数据库,随后在管理员访问后台统计页面时被拼接进查询并执行,从而读取数据库中的敏感信息。

利用条件与风险

利用无需认证,但注入需等待管理员查看流量来源仪表盘才被触发,属于存储型延迟利用;成功利用可导致数据库敏感信息泄露。

修复建议

官方修复方案暂无公开信息,建议关注插件官方更新并及时升级;临时缓解可限制对 wmcTrack 跟踪端点的访问或对 referrer 参数进行严格过滤与转义。

原始情报

The WP Visitor Statistics (Real Time Traffic) plugin for WordPress is vulnerable to generic SQL Injection via the ‘fullRef’ parameter in all versions up to, and including, 8.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This is a second-order SQL injection: an unauthenticated attacker submits a crafted referrer URL to the wmcTrack tracking endpoint, which persists the raw unescaped value into the wp_logVisit table, and the injection is triggered when an administrator next views the Traffic Sources dashboard.