peter bassill · operator
$ cve CVE-2015-5533 JSON

CVE-2015-5533 EXPLOIT

7.2
HIGH · CVSS 3.0 · EPSS 7.2% (pctl 94)

Patch early

A public exploit exists.

Description

SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

Scoring

CVSS7.2 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS7.17% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2017-10-23
Last modified2026-06-17

Affected (1)

VendorProduct
count per day projectcount per day

Public exploits

SourceTitleDate
exploit-dbWordPress Plugin Count Per Day 3.4 - SQL Injection2015-07-27

References

→ the Explorer  ·  watch your stack  ·  NVD