QID 730429

Date Published: 2022-04-08

QID 730429: WordPress Plugin WP Visitor Statistics SQL Injection Vulnerability

WP Visitor Statistics (Real Time Traffic) or Wp-Stats-Manager plugin will help you to track your visitors, browsers, operating systems, visits and much more in one dashboard page.

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection.

Affected Versions:
WP Visitor Statistics (Real Time Traffic) or Wp-Stats-Manager versions prior to 5.6.
QID Detection Logic:(Unauthenticated)
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the WP Visitor Statistics (Real Time Traffic) or Wp-Stats-Manager plugin.

Successful exploitation of this vulnerability may allow an authenticated remote attacker to execute arbitrary SQL queries on the affected targets.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Customers are requested to update to WP Visitor Statistics (Real Time Traffic) or Wp-Stats-Manager 5.6 or later to mitigate this vulnerability.

    Vendor References

    CVEs related to QID 730429

    Software Advisories
    Advisory ID Software Component Link
    Wp Stats Manager Release Notes URL Logo wordpress.org/plugins/wp-stats-manager/advanced/