Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
wp statistics vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-0600
The WP Visitor Statistics (Real Time Traffic) WordPress plugin prior to 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
Plugins-market Wp Visitor Statistics
9.8
CVSSv3
CVE-2022-33965
Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.
Plugins-market Wp Visitor Statistics
9.8
CVSSv3
CVE-2022-25148
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL que...
Veronalabs Wp Statistics
9.8
CVSSv3
CVE-2017-18515
The wp-statistics plugin prior to 12.0.8 for WordPress has SQL injection.
Veronalabs Wp Statistics
9.8
CVSSv3
CVE-2019-13275
An issue exists in the VeronaLabs wp-statistics plugin prior to 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.
Veronalabs Wp Statistics
8.8
CVSSv3
CVE-2023-0955
The WP Statistics WordPress plugin prior to 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a setti...
Veronalabs Wp Statistics
8.8
CVSSv3
CVE-2022-38074
SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.
Veronalabs Wp Statistics
8.8
CVSSv3
CVE-2022-4230
The WP Statistics WordPress plugin prior to 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a set...
Veronalabs Wp Statistics
8.8
CVSSv3
CVE-2022-0410
The WP Visitor Statistics (Real Time Traffic) WordPress plugin prior to 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection
Wp Visitor Statistics Project Wp Visitor Statistics
8.8
CVSSv3
CVE-2021-24750
The WP Visitor Statistics (Real Time Traffic) WordPress plugin prior to 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attac...
Wp Visitor Statistics \\(real Time Traffic\\) Project Wp Visitor Statistics \\(real Time Traffic\\)
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-22120
CVE-2024-35921
CVE-2024-35874
brute force
CVE-2024-36080
unprivileged
CVE-2024-35917
IDOR
CVE-2024-4947
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »