Skip to content

Known CVE

WP Visitor Statistics (Real Time Traffic) < 6.9 - SQL Injection

The plugin does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.

CVE-2023-0600

Critical2023CVSS 9.8CWE-89

time-based-sqli · cve2023 · wp · wp-plugin · wordpress · wpscan · unauth · wp-stats-manager

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website