天下漏洞,尽知其名
HIGH

CVE-2026-97341 WordPress Visitor Traffic Real Time Statistics 存储型 DOM XSS 漏洞

影响未授权攻击者可注入恶意脚本,在用户访问页面时执行

AI 研判

WordPress 插件 Visitor Traffic Real Time Statistics 在所有 8.16 及之前版本中存在存储型 DOM 型跨站脚本漏洞。漏洞源于对 X-Real-IP HTTP 请求头输入过滤与输出转义不足,未授权攻击者可通过伪造该请求头注入任意脚本。

影响范围

WordPress Visitor Traffic Real Time Statistics

受影响版本为 Visitor Traffic Real Time Statistics 插件 8.16 及之前的所有版本,暂无更细化的版本范围公开信息。

漏洞详情

该漏洞属于存储型 DOM 型 XSS。插件通过 wp_ajax_nopriv_ahcfree_track_visitor 接口接收未认证请求,未对 X-Real-IP 请求头做充分过滤,将实体编码后的载荷原样存入数据库,随后在页面渲染时被 DOM 解析执行。攻击者无需认证、nonce 或权限即可投递恶意脚本。

利用条件与风险

利用无需任何认证或权限,攻击者仅需构造带恶意 X-Real-IP 头的 HTTP 请求即可投递载荷,实战中可劫持会话或窃取敏感信息,风险较高。

修复建议

建议升级至官方修复版本;若暂无补丁,可临时禁用或移除该插件,并对 X-Real-IP 等请求头进行严格过滤与输出转义。

原始情报

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via ‘X-Real-IP’ HTTP Header in all versions up to, and including, 8.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires no authentication, no nonce, and no capability — the wp_ajax_nopriv_ahcfree_track_visitor endpoint accepts the forged X-Real-IP header from any unauthenticated HTTP request and stores the entity-encoded payload verbatim in the database.