CVE-2023-0600

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:plugins-market:wp_visitor_statistics:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:37

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4 - Exploit () https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4 - Exploit

07 Nov 2023, 04:00

Type Values Removed Values Added
CWE CWE-89

Information

Published : 2023-05-15 13:15

Updated : 2024-11-21 07:37


NVD link : CVE-2023-0600

Mitre link : CVE-2023-0600

CVE.ORG link : CVE-2023-0600


JSON object : View

Products Affected

plugins-market

  • wp_visitor_statistics
CWE

No CWE.