Page Views Count < 2.4.15 - Unauthenticated SQL Injection
45Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 15%
from disclosure to weapon
Published on NVDMar 7
VulnCheck+1188d
exploitation probability
15%top 4% of all CVEs
observed exploitation
yesVulnCheck
The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks
Affected products
Unknown · Page View Count