WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection
72Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 38%
from disclosure to weapon15 days
Published on NVDDec 21
1st PoC+15d
VulnCheck+161d
exploitation probability
38%top 2% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks
Affected products
Unknown · WP Visitor Statistics (Real Time Traffic)public PoCs found — 3
exploitdbwww.exploit-db.com/exploits/50619unverifiedcve_referencepacketstormsecurity.com/files/165433/WordPress-WP-Visitor-Statistics-4.7-SQL-Injection.htmlunverifiedvulncheckvulncheck.com/xdb/687ae0b268c6unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.