.. / CVE-2022-33965

Exploit for WordPress Visitor Statistics <=5.7 - SQL Injection (CVE-2022-33965)

Description:

WordPress Visitor Statistics plugin through 5.7 contains multiple unauthenticated SQL injection vulnerabilities. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Nuclei Template

View the template here CVE-2022-33965.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-33965.yaml
Copy

References:

https://wordpress.org/plugins/wp-stats-manager/
https://wordpress.org/plugins/wp-stats-manager/#developers
https://patchstack.com/database/vulnerability/wp-stats-manager/wordpress-wp-visitor-statistics-plugin-5-7-multiple-unauthenticated-sql-injection-sqli-vulnerabilities
https://nvd.nist.gov/vuln/detail/CVE-2022-33965
https://github.com/20142995/sectool