Record summary

CVE-2020-5766 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 12, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

SRS Simple Hits Counter Plugin for WordPress

CVE List1.0.3, 1.0.4affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHSRS Simple Hits Counter 1.0.3-1.0.4 - Unauthenticated Blind SQL InjectionCVSS 7.5

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.

Impact

Unauthenticated attackers can extract database contents via blind SQL injection, potentially exposing sensitive WordPress user data and credentials.

Remediation

Update to the latest version of SRS Simple Hits Counter plugin.

WeaknessesCWE-89
AuthorsDhiyaneshDk
Template tagscvecve2020srs-simple-hits-counterwordpresswpwp-plugintime-based-sqlisqlivkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:srs_simple_hits_counter_project:srs_simple_hits_counter:1.0.3:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2