← back
CVE-2021-24750observed exploitationCWE-89

WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection

72Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 38%
from disclosure to weapon15 days
Published on NVDDec 21
1st PoC+15d
VulnCheck+161d
exploitation probability
38%top 2% of all CVEs
observed exploitation
yesVulnCheck
3 public exploit(s)
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.