QID 730429
Date Published: 2022-04-08
QID 730429: WordPress Plugin WP Visitor Statistics SQL Injection Vulnerability
WP Visitor Statistics (Real Time Traffic) or Wp-Stats-Manager plugin will help you to track your visitors, browsers, operating systems, visits and much more in one dashboard page.
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection.
Affected Versions:
WP Visitor Statistics (Real Time Traffic) or Wp-Stats-Manager versions prior to 5.6.
QID Detection Logic:(Unauthenticated)
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the WP Visitor Statistics (Real Time Traffic) or Wp-Stats-Manager plugin.
Successful exploitation of this vulnerability may allow an authenticated remote attacker to execute arbitrary SQL queries on the affected targets.
- Wp Stats Manager Release Notes -
wordpress.org/plugins/wp-stats-manager/advanced/
CVEs related to QID 730429
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Wp Stats Manager Release Notes |
|