CVE-2023-0600
CRITICAL 9.8EPSS 4.2%
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 4.23% chance of exploitation in the next 30 days, 90th percentile
- Nuclei
- critical · CWE-89
- Published
- 2023-05-15
- Updated
- 2025-01-24