QID 730497
Date Published: 2022-05-24
QID 730497: WordPress Plugin Page View Count SQL Injection Vulnerability
WordPress Page View Count plugin is simple to set up plugin that gives site visitors and site owners the ability to quickly and easily see how many people have visited that page or post.
CVE-2022-0434: The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks.
Affected Version:
Page View Count plugin versions prior to 2.4.15
QID Detection Logic(Unauthenticated): This unauthenticated detection will send a malicious query to post_ids parameter and tries to fetch the email from the system or detection also depends on the BlindElephant engine to detect the vulnerable version of the Page View Count plugin.
Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary SQL queries on the target system.
- Page View Count Release Notes -
wordpress.org/plugins/page-views-count/#developers
CVEs related to QID 730497
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Page View Count Release Notes |
|