Vulnerabilities > WP BUY > Visitor Traffic Real Time Statistics > 3.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-11-08 | CVE-2021-24829 | SQL Injection vulnerability in Wp-Buy Visitor Traffic Real Time Statistics The Visitor Traffic Real Time Statistics WordPress plugin before 3.9 does not validate and escape user input passed to the today_traffic_index AJAX action (available to any authenticated users) before using it in a SQL statement, leading to an SQL injection issue | 8.8 |