PoC Index

CVE-2021-24750

HIGH 8.8EPSS 38.3%

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

CVSS v3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
38.30% chance of exploitation in the next 30 days, 98th percentile
Nuclei
high · CWE-89
Published
2021-12-21
Updated
2024-08-03

Proof-of-concept exploits (3)

Nuclei templates (1)

ExploitDB entries (1)

References

Related