9.8
CVE-2023-0600
- EPSS 77.4%
- Veröffentlicht 15.05.2023 13:15:09
- Zuletzt bearbeitet 24.01.2025 21:15:08
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
WP Visitor Statistics (Real Time Traffic) <= 6.8.1 - Unauthenticated SQL Injection
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
Mögliche Gegenmaßnahme
WP Visitor Statistics (Real Time Traffic): Update to version 6.9, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WP Visitor Statistics (Real Time Traffic)
Version
*-6.8.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Plugins-market ≫ Wp Visitor Statistics SwPlatformwordpress Version < 6.9
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 77.4% | 0.989 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|