peter bassill · operator
$ cve CVE-2021-24750 JSON

CVE-2021-24750 EXPLOIT

8.8
HIGH · CVSS 3.1 · EPSS 38.3% (pctl 99)

Patch early

A public exploit exists.

Description

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

Scoring

CVSS8.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS38.3% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2021-12-21
Last modified2026-06-17

Affected (1)

VendorProduct
codepressvisitor statistics

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD