WP Visitor Statistics (Real Time Traffic) < 6.9 - SQL Injection
The plugin does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
wp_visitor_statisticsPoC 已收录
CVSS9.8EPSS 74.1%