Vulnerability Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determine the value of database fields.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Srs Simple Hits Counter Project | Srs Simple Hits Counter | 1.0.3 |
Related Weaknesses (CWE)
References
- https://www.tenable.com/security/research/tra-2020-42ExploitThird Party Advisory
- https://www.tenable.com/security/research/tra-2020-42ExploitThird Party Advisory
FAQ
What is CVE-2020-5766?
CVE-2020-5766 is a vulnerability with a CVSS score of 7.5 (HIGH). Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in SRS Simple Hits Counter Plugin for WordPress 1.0.3 and 1.0.4 allows a remote, unauthenticated attacker to determ...
How severe is CVE-2020-5766?
CVE-2020-5766 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5766?
Check the references section above for vendor advisories and patch information. Affected products include: Srs Simple Hits Counter Project Srs Simple Hits Counter.