What the vulnerability does
01Description
Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
What the vulnerability does
Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.
Explanation of Vulnerability in Simple Terms
WP Visitor Statistics versions 5.7 and earlier contain a SQL injection vulnerability in the plugin's database queries. An unauthenticated attacker can inject malicious SQL code through the plugin's input parameters, potentially reading sensitive data from the WordPress database or modifying site content. The vulnerability requires no user interaction and can be exploited remotely.
What an attacker can do
Read or modify data in the WordPress database, including user credentials and site configuration.
Potential impact on your site
Attackers can steal user data, modify posts/pages, or compromise site integrity without needing a WordPress account.
Conditions required to exploit
Network access to the WordPress site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities