{"api_version":"1","generated_at":"2026-07-23T18:59:10+00:00","cve":"CVE-2023-0600","urls":{"html":"https://cve.report/CVE-2023-0600","api":"https://cve.report/api/cve/CVE-2023-0600.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-0600","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-0600"},"summary":{"title":"CVE-2023-0600","description":"The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2023-05-15 13:15:00","updated_at":"2023-11-07 04:00:00"},"problem_types":[],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4","name":"https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4","refsource":"MISC","tags":[],"title":"WP Visitor Statistics (Real Time Traffic) < 6.9 - Unauthenticated SQLi WordPress Security Vulnerability","mime":"text/html","httpstatus":"403","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-0600","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-0600","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"600","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"plugins-market","cpe5":"wp_visitor_statistics","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-0600","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-89 SQL Injection"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"WP Visitor Statistics (Real Time Traffic)","version":{"version_data":[{"version_affected":"<","version_name":"0","version_value":"6.9"}]}}]}}]}},"references":{"reference_data":[{"url":"https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4","refsource":"MISC","name":"https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4"}]},"generator":{"engine":"WPScan CVE Generator"},"source":{"discovery":"EXTERNAL"},"credits":[{"lang":"en","value":"Trần Quốc Trường An"},{"lang":"en","value":"WPScan"}]},"nvd":{"publishedDate":"2023-05-15 13:15:00","lastModifiedDate":"2023-11-07 04:00:00","problem_types":[],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:plugins-market:wp_visitor_statistics:*:*:*:*:*:wordpress:*:*","versionEndExcluding":"6.9","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}