PoC Index

CVE-2023-0600

CRITICAL 9.8EPSS 4.2%

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
4.23% chance of exploitation in the next 30 days, 90th percentile
Nuclei
critical · CWE-89
Published
2023-05-15
Updated
2025-01-24

Proof-of-concept exploits (1)

Nuclei templates (1)

References

Related