S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-33965 Scanner

CVE-2022-33965 scanner - SQL Injection vulnerability in Osamaesh WP Visitor Statistics plugin for Wordpress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-33965
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WP Visitor Statistics (WordPress plugin)by Osamaesh
<= 5.7
Updated Aug 22, 2026View on NVD →
Detail

Osamaesh WP Visitor Statistics is a WordPress plugin that provides detailed statistics of the visitors to a website. It is designed to help website owners monitor their traffic and better understand their audience. The plugin displays user information such as IP address, location, browser, and operating system.

CVE-2022-33965 is a critical SQL Injection vulnerability that has been detected in this plugin. Cyber attackers can exploit this vulnerability by injecting malicious code into the website's database using specially crafted SQL queries. As a result, they can gain access to sensitive information such as usernames, passwords, and credit card details. This sensitive information can then be used for fraudulent activities or sold on the dark web.

The consequences of this vulnerability can be devastating for individuals and businesses alike. If left unpatched, the damage can be multiplied, from compromised website integrity to data breaches. Website owners must act quickly to protect themselves and their users from the potential consequences of this vulnerability.

At s4e.io, we offer a comprehensive and professional suite that helps individuals and businesses alike protect their online assets. With a range of pro features under the hood, website owners can quickly and easily identify vulnerabilities without requiring a detailed understanding of cybersecurity principles. Choose s4e.io today to secure your digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended that website owners take the following precautions:

  • Update the plugin to the latest version as soon as possible
  • Routinely check the website for unusual activity
  • Implement a web application firewall (WAF)
  • Implement secure coding practices, such as parameterized queries, to prevent SQL injection attacks
  • Create strong passwords and enable two-factor authentication

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-33965 scanner - SQL Injection vulnerability in Osamaesh WP Visitor Statistics plugin for Wordpress | S4E