Impact
The WP Visitor Statistics (Real Time Traffic) plugin contains a second‑order SQL injection flaw in the 'fullRef' parameter. An unauthenticated attacker can inject crafted SQL through a referrer URL that is stored in the wp_logVisit table, and the injection is triggered the next time an administrator views the Traffic Sources dashboard. This allows the attacker to read sensitive information from the WordPress database, such as user data or site configuration, but does not provide code execution or immediate denial of service.
Affected Systems
WordPress sites running the WP Visitor Statistics (Real Time Traffic) plugin by osamaesh, versions 8.7 and earlier, are affected. Any WordPress installation that has not applied a patch that removes the unescaped 'fullRef' parameter in these plugin versions is vulnerable.
Risk and Exploitability
The CVSS score for this vulnerability is 7.5, indicating a high risk to confidentiality. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated access: a malicious actor can craft a referrer URL and host it, after which a site administrator's visit to the Traffic Sources dashboard will trigger the injected SQL. Because the exploit requires an admin to view the dashboard, an attacker may need to wait for or entice an admin’s interaction, but given the ubiquity of such dashboards, exploitation is feasible and can result in disclosure of sensitive database contents.
OpenCVE Enrichment