vendor:
Count Per Day WordPress plugin
by:
High-Tech Bridge Security Research Lab
7.2
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Count Per Day WordPress plugin
Affected Version From: 3.4 and probably prior
Affected Version To: 3.4
Patch Exists: YES
Related CWE: CVE-2015-5533
CPE: a:tom_braider:count_per_day_wordpress_plugin
Platforms Tested:
2015
Count Per Day WordPress plugin SQL Injection Vulnerability
The SQL Injection vulnerability in the Count Per Day WordPress plugin allows remote attackers with administrative privileges to execute arbitrary SQL commands and gain control of sensitive information in the application's database. The vulnerability is caused by insufficient filtration of input data passed via the 'cpd_keep_month' HTTP POST parameter to the '/wp-admin/options-general.php' script. An attacker can exploit this vulnerability through a CSRF vector since the application does not check the origin of HTTP requests.
Mitigation:
The vulnerability has been fixed by the vendor. Users are advised to update to the latest patched version of the Count Per Day WordPress plugin.