Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2022-0410

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 5.6 does not sanitise and escape the id parameter before using it in a SQL statement via the refUrlDetails AJAX action, available to any authenticated user, leading to a SQL injection
Attacker Value
Unknown

CVE-2021-24750

Disclosure Date: December 21, 2021 (last updated February 23, 2025)
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks
Attacker Value
Unknown

CVE-2017-10991

Disclosure Date: July 07, 2017 (last updated November 08, 2023)
The WP Statistics plugin through 12.0.9 for WordPress has XSS in the rangestart and rangeend parameters on the wps_referrers_page page.
0
Attacker Value
Unknown

CVE-2017-2136

Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
0
Attacker Value
Unknown

CVE-2017-2135

Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-2147

Disclosure Date: April 28, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0