CVE-2023-0600

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:plugins-market:wp_visitor_statistics:*:*:*:*:*:wordpress:*:*

History

24 Jan 2025, 21:15

Type Values Removed Values Added
References (MISC) https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4 - Exploit () https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4 - Exploit

07 Nov 2023, 04:00

Type Values Removed Values Added
CWE CWE-89

23 May 2023, 16:00

Type Values Removed Values Added
CPE cpe:2.3:a:plugins-market:wp_visitor_statistics:*:*:*:*:*:wordpress:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4 - (MISC) https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4 - Exploit
First Time Plugins-market wp Visitor Statistics
Plugins-market

15 May 2023, 13:26

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-15 13:15

Updated : 2025-01-24 21:15


NVD link : CVE-2023-0600

Mitre link : CVE-2023-0600


JSON object : View

Products Affected

plugins-market

  • wp_visitor_statistics
CWE

No CWE.