Sploitus

CVE-2021-24750

4 known exploits for CVE-2021-24750

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

Affected products
Wp Visitor Statistics
Codepress Visitor Statistics
< 4.8
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
38.3% (98th percentile)
Weakness
CWE-89
NVD status
Modified
Published
2021-12-21
CVE-2021-24750 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2021-24750

Proof-of-concept code and exploit modules indexed by Sploitus