CVE-2023-0600

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:codepress:visitor_statistics:*:*:*:*:-:wordpress:*:*

History

06 Mar 2026, 19:34

Type Values Removed Values Added
CPE cpe:2.3:a:plugins-market:wp_visitor_statistics:*:*:*:*:*:wordpress:*:* cpe:2.3:a:codepress:visitor_statistics:*:*:*:*:-:wordpress:*:*
First Time Codepress
Codepress visitor Statistics
CWE CWE-89

21 Nov 2024, 07:37

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4 - Exploit () https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4 - Exploit

07 Nov 2023, 04:00

Type Values Removed Values Added
CWE CWE-89

23 May 2023, 16:00

Type Values Removed Values Added
CPE cpe:2.3:a:plugins-market:wp_visitor_statistics:*:*:*:*:*:wordpress:*:*
First Time Plugins-market wp Visitor Statistics
Plugins-market
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4 - (MISC) https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4 - Exploit

15 May 2023, 13:26

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-15 13:15

Updated : 2026-03-06 19:34


NVD link : CVE-2023-0600

Mitre link : CVE-2023-0600

CVE.ORG link : CVE-2023-0600


JSON object : View

Products Affected

codepress

  • visitor_statistics
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')