CVE-2023-0600
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
- Affected products
- Wp Visitor Statistics
- Codepress Visitor Statistics
- < 6.9
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 4.2% (90th percentile)
- Weakness
- CWE-89
- NVD status
- Analyzed
- Published
- 2023-05-15
CVE-2023-0600 at NVD
1 known exploit for CVE-2023-0600
Proof-of-concept code and exploit modules indexed by Sploitus