{"api_version":"1","generated_at":"2026-07-23T20:08:14+00:00","cve":"CVE-2021-24750","urls":{"html":"https://cve.report/CVE-2021-24750","api":"https://cve.report/api/cve/CVE-2021-24750.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-24750","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-24750"},"summary":{"title":"CVE-2021-24750","description":"The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2021-12-21 09:15:00","updated_at":"2022-08-04 16:19:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"http://packetstormsecurity.com/files/165433/WordPress-WP-Visitor-Statistics-4.7-SQL-Injection.html","name":"http://packetstormsecurity.com/files/165433/WordPress-WP-Visitor-Statistics-4.7-SQL-Injection.html","refsource":"MISC","tags":[],"title":"WordPress WP Visitor Statistics 4.7 SQL Injection ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://plugins.trac.wordpress.org/changeset/2622268","name":"https://plugins.trac.wordpress.org/changeset/2622268","refsource":"CONFIRM","tags":[],"title":"403 Forbidden","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://wpscan.com/vulnerability/7528aded-b8c9-4833-89d6-9cd7df3620de","name":"https://wpscan.com/vulnerability/7528aded-b8c9-4833-89d6-9cd7df3620de","refsource":"MISC","tags":[],"title":"Attention Required! | Cloudflare","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-24750","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-24750","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Krzysztof Zając","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"24750","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"plugins-market","cpe5":"wp_visitor_statistics_\\(real_time_traffic\\)","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"24750","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wp_visitor_statistics_\\(real_time_traffic\\)_project","cpe5":"wp_visitor_statistics_\\(real_time_traffic\\)","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ID":"CVE-2021-24750","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC","TITLE":"WP Visitor Statistics (Real Time Traffic) < 4.8 - Subscriber+ SQL Injection"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","generator":"WPScan CVE Generator","affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"WP Visitor Statistics (Real Time Traffic)","version":{"version_data":[{"version_affected":"<","version_name":"4.8","version_value":"4.8"}]}}]}}]}},"description":{"description_data":[{"lang":"eng","value":"The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks"}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://wpscan.com/vulnerability/7528aded-b8c9-4833-89d6-9cd7df3620de","name":"https://wpscan.com/vulnerability/7528aded-b8c9-4833-89d6-9cd7df3620de"},{"refsource":"CONFIRM","url":"https://plugins.trac.wordpress.org/changeset/2622268","name":"https://plugins.trac.wordpress.org/changeset/2622268"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/165433/WordPress-WP-Visitor-Statistics-4.7-SQL-Injection.html","url":"http://packetstormsecurity.com/files/165433/WordPress-WP-Visitor-Statistics-4.7-SQL-Injection.html"}]},"problemtype":{"problemtype_data":[{"description":[{"value":"CWE-89 SQL Injection","lang":"eng"}]}]},"credit":[{"lang":"eng","value":"Krzysztof Zając"}],"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2021-12-21 09:15:00","lastModifiedDate":"2022-08-04 16:19:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:wp_visitor_statistics_\\(real_time_traffic\\)_project:wp_visitor_statistics_\\(real_time_traffic\\):*:*:*:*:*:wordpress:*:*","versionEndExcluding":"4.8","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"24750","Ordinal":"199512","Title":"CVE-2021-24750","CVE":"CVE-2021-24750","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"24750","Ordinal":"1","NoteData":"The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks","Type":"Description","Title":null},{"CveYear":"2021","CveId":"24750","Ordinal":"2","NoteData":"2021-12-21","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"24750","Ordinal":"3","NoteData":"2022-01-05","Type":"Other","Title":"Modified"}]}}}