Impact
The vulnerability is an unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro versions 11.17 and older. It allows an attacker to inject arbitrary SQL statements through user input in the plugin, which can result in unauthorized data access or tampering.
Affected Systems
WordPress sites running the Visitor Traffic Real Time Statistics Pro plugin from CODEPRESS IT Solutions LLC with a version of 11.17 or earlier are affected. All releases in that range are vulnerable; no further version details are specified.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. With no EPSS score available, the likelihood of exploitation cannot be precisely quantified, but the unauthenticated nature of the flaw and its 9.3 rating suggest it is likely to be actively exploited. The vulnerability is not listed in CISA KEV. An attacker would trigger it via HTTP requests to the website without authentication, sending crafted parameters that the plugin processes unsafely. Successful exploitation could lead to full compromise of the application database.
OpenCVE Enrichment