cleantalk
Vulnerabilities and Security Researches

WP Visitor Statistics (Real Time Traffic), CVE-2022-0410

CVE, Research URL

CVE-2022-0410

Published on
Mar 07, 2022
Research Description
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection
Affected versions
Min -, max 5.6.
Status
vulnerable