CVE-2023-0600 identifies a critical SQL Injection vulnerability (CWE-89) in the WP Visitor Statistics (Real Time Traffic) WordPress plugin, affecting versions before 6.9. This flaw allows unauthenticated attackers to execute arbitrary SQL queries by exploiting unescaped user input, resulting in a CVSS score of 9.8 (Critical) due to potential complete compromise of confidentiality, integrity, and availability. Although not currently on CISA's KEV catalog, its high EPSS score and FAUCET Risk Score of 84/100 indicate significant risk. While no Metasploit or ExploitDB modules are publicly available, Nuclei templates exist, suggesting a path for potential exploitation despite limited community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.9CPE matchmatch criteria | cpe:2.3:a:codepress:visitor_statistics:*:*:*:*:-:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.