Showing 2 vulnerabilities on this page for visitor_statistics

Signals CISA KEV Ransomware Nuclei
codepress vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WP Visitor Statistics (Real Time Traffic) < 6.9 - Unauthenticated SQLi

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

CWE-89May 15, 20231 related artifact
CVSS9.8v3.1EPSS4.23%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CWE-89Dec 21, 20211 related artifact
CVSS8.8v3.1EPSS38.3%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX