Record summary

CVE-2023-0600 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 10, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 24, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

WP Visitor Statistics (Real Time Traffic)

Default status: unaffected

CVE ListBefore 6.9affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryCRITICALWP Visitor Statistics (Real Time Traffic) < 6.9 - SQL InjectionCVSS 9.8

The plugin does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

Impact

Unauthenticated attackers can execute time-based SQL injection through the visitorId parameter to extract the complete WordPress database including user credentials and site statistics.

Remediation

Fixed in version 6.9

WeaknessesCWE-89
Authorsr3Y3r53, j4vaovo
Template tagstime-based-sqlicvecve2023wpwp-pluginwordpresswpscanunauthwp-stats-managersqliplugins-marketvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:plugins-market:wp_visitor_statistics:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"wp-stats-manager"
FOFA: body="wp-stats-manager"
Google: inurl:"/wp-content/plugins/wp-stats-manager"

Source: ProjectDiscovery

References

2