CVE-2023-0600: Codepress Visitor Statistics
Critical severity, CVSS 9.8. EPSS: 4.2% chance of exploitation in the next 30 days.
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 6.9 does not escape user input which is concatenated to an SQL query, allowing unauthenticated visitors to conduct SQL Injection attacks.
Affected products
- Codepress Visitor Statistics: before 6.9 (fixed in 6.9)
Published 2023-05-15. Last modified 2026-06-17.