PT-2020-18687 · WordPress · Srs Simple Hits Counter Plugin

Published

2020-07-13

·

Updated

2025-06-09

·

CVE-2020-5766

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SRS Simple Hits Counter Plugin for WordPress versions 1.0.3 through 1.0.4
Description The issue is related to SQL Injection, where improper neutralization of special elements used in an SQL command allows a remote, unauthenticated attacker to determine the value of database fields.
Recommendations For SRS Simple Hits Counter Plugin for WordPress versions 1.0.3 and 1.0.4, update to a version that fixes the SQL Injection issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2020-5766

Affected Products

Srs Simple Hits Counter Plugin