Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wp statistics vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2019-10864
The WP Statistics plugin up to and including 12.6.2 for WordPress has XSS, allowing a remote malicious user to inject arbitrary web script or HTML via the Referer header of a GET request.
Veronalabs Wp Statistics
9.8
CVSSv3
CVE-2022-25148
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL que...
Veronalabs Wp Statistics
7.5
CVSSv3
CVE-2022-25149
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtai...
Veronalabs Wp Statistics
6.1
CVSSv3
CVE-2022-25305
The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows malicious users to inject arbitrary web scripts onto several pages that ...
Veronalabs Wp Statistics
8.8
CVSSv3
CVE-2023-0955
The WP Statistics WordPress plugin prior to 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a setti...
Veronalabs Wp Statistics
9.8
CVSSv3
CVE-2023-0600
The WP Visitor Statistics (Real Time Traffic) WordPress plugin prior to 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
Plugins-market Wp Visitor Statistics
5.4
CVSSv3
CVE-2022-4656
The WP Visitor Statistics (Real Time Traffic) WordPress plugin prior to 6.5 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Plugins-market Wp Visitor Statistics
9.8
CVSSv3
CVE-2022-33965
Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.
Plugins-market Wp Visitor Statistics
8.8
CVSSv3
CVE-2021-24193
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin prior to 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arb...
Wp-buy Visitor Traffic Real Time Statistics
8.8
CVSSv3
CVE-2019-15831
The visitors-traffic-real-time-statistics plugin prior to 1.12 for WordPress has CSRF in the settings page.
Wp-buy Visitor Traffic Real Time Statistics
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-23316
SQL injection
type confusion
CVE-2024-20697
CVE-2024-4344
local
CVE-2024-30043
CVE-2024-3821
CVE-2024-5041
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »