Vulnerabilities
Vulnerable Software
The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue
CVSS Score
8.8
EPSS Score
0.007
Published
2021-11-08
Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time Statistics WordPress plugin before 2.12, to install any plugin (including a specific version) from the WordPress repository, as well as activate arbitrary plugin from then blog, which helps attackers install vulnerable plugins and could lead to more critical vulnerabilities like RCE.
CVSS Score
8.8
EPSS Score
0.006
Published
2021-05-14
The visitors-traffic-real-time-statistics plugin before 1.12 for WordPress has CSRF in the settings page.
CVSS Score
8.8
EPSS Score
0.001
Published
2019-08-30
The visitors-traffic-real-time-statistics plugin before 1.13 for WordPress has CSRF.
CVSS Score
8.8
EPSS Score
0.002
Published
2019-08-30


Contact Us

Shodan ® - All rights reserved