WP Visitor Statistics (Real Time Traffic) < 5.6 - Subscriber+ SQL Injection
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.3%
exploitation probability
1.3%top 32% of all CVEs
observed exploitation
nono source reports it
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection
Affected products
Unknown · WP Visitor Statistics (Real Time Traffic)