S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24750 Scanner

CVE-2021-24750 scanner - SQL Injection (SQLi) vulnerability in Visitor Statistics (Real Time Traffic) plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.5k
Times Used
continuous scan runs
4.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24750
8.8
CVSS

The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WP Visitor Statistics (Real Time Traffic)
AFFECTED< 4.8SAFE ✓≥ 4.8
Updated Aug 21, 2026View on NVD →
Detail

The WP Visitor Statistics (Real Time Traffic) plugin is used by WordPress site administrators to track traffic to their site in real-time. This plugin provides users with valuable information about the number of visitors to their site, the pages that are visited frequently, and the duration of each visit. This data can be used to optimize the site's content and improve the user experience. 

CVE-2021-24750 is a vulnerability detected in the WP Visitor Statistics (Real Time Traffic) plugin, which puts the security of the site at risk. This vulnerability arises because of improper sanitization and escaping of refUrl in the refDetails AJAX action, which is accessible to any authenticated user. Even users with a low-level role, such as a subscriber, can exploit this vulnerability, potentially leading to disastrous consequences. 

When exploited, this vulnerability can allow attackers to perform SQL injection attacks. As a result, they can gain unauthorized access to the site's database, steal sensitive user data, and compromise the site's security. This vulnerability can be very dangerous, particularly for sites that deal with confidential or financial information. 

In conclusion, the WP Visitor Statistics (Real Time Traffic) plugin is a valuable tool for WordPress site administrators. However, the CVE-2021-24750 vulnerability can put your site's security at risk. By following the above precautions and using a security plugin like s4e.io, you can quickly and effectively protect your site from potential threats. Don't let vulnerabilities go unnoticed - take action today to safeguard your digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken:

  • Keep your site and plugins up to date with the latest releases.
  • Use secure passwords and two-factor authentication to maintain strict access control.
  • Limit the user roles and permissions to ensure that lower-level users cannot access sensitive data.
  • Use firewalls and intrusion detection systems to monitor and prevent potential attacks.
  • Install a security plugin like securityforeveryone.com, which can scan your site for vulnerabilities and provide you with real-time alerts and recommendations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24750 scanner - SQL Injection (SQLi) vulnerability in Visitor Statistics (Real Time Traffic) plugin for WordPress | S4E