The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2021-12-21T08:45:29

Updated: 2022-01-05T18:06:16

Reserved: 2021-01-14T00:00:00


Link: CVE-2021-24750

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-12-21T09:15:06.987

Modified: 2022-08-04T16:19:47.890


Link: CVE-2021-24750

JSON object: View

cve-icon Redhat Information

No data.

CWE