WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress的WP Visitor Statistics (Real Time Traffic)插件 4.8之前版本存在SQL注入漏洞,该漏洞源于插件没有正确地清理和转义refDetails AJAX动作中的refUrl,攻击者可利用该漏洞执行SQL注入攻击.
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Visitor Statistics (Real Time Traffic) | 4.8 ~ 4.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Demonstration of the WP Visitor Statistics plugin exploit | https://github.com/fimtow/CVE-2021-24750 | POC Details |
| 2 | WordPress Visitor Statistics (Real Time Traffic) plugin before 4.8 does not properly sanitize and escape the refUrl in the refDetails AJAX action, which is available to any authenticated user. This could allow users with a role as low as subscriber to perform SQL injection attacks. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-24750.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2021-24981 | Directorist – Business Directory Plugin < 7.0.6.2 - CSRF to Remote File Upload | |
| CVE-2021-24956 | Blog2Social < 6.8.7 - Reflected Cross-Site Scripting | |
| CVE-2021-24941 | Icegram < 2.0.5 - Reflected Cross-Site Scripting | |
| CVE-2021-24907 | Everest Forms < 1.8.0 - Reflected Cross-Site Scripting | |
| CVE-2021-24849 | WCFM - WooCommerce Multivendor Marketplace < 3.4.12 - Unauthenticated SQL Injection | |
| CVE-2021-24846 | Ni WooCommerce Custom Order Status < 1.9.7 - Subscriber+ SQL Injection | |
| CVE-2021-24739 | Logo Carousel < 3.4.2 - Unauthorised Private Post Access | |
| CVE-2021-24738 | Logo Carousel < 3.4.2 - Contributor+ Stored Cross-Site Scripting | |
| CVE-2021-24578 | SportsPress < 2.7.9 - Reflected Cross-Site Scripting |
No comments yet