Critical SQL Injection Vulnerability Affects Advanced Page Visit Counter Plugin for WordPress
A recently discovered SQL Injection vulnerability (CVE-2023-45074) has been identified in the Advanced Page Visit Counter Most Wanted Analytics Plugin for WordPress. This security flaw, if exploited, could lead to unauthorized access, data theft, and potential website disruption.
Impact and Severity
The vulnerability, with a base score of 9.8 on the Common Vulnerability Scoring System (CVSS), is considered critical. The flaw affects versions of the Advanced Page Visit Counter plugin from n/a through 7.1.1.
Relevance to North East India and India
WordPress is widely used across India, including the North East region, for website development and management. Given the popularity of WordPress, it is crucial for users in the North East to ensure their websites are protected against such vulnerabilities.
Vulnerability Details
The SQL Injection vulnerability allows attackers to inject malicious SQL commands into the plugin, potentially gaining unauthorized access to sensitive data, such as user information and website configuration details.
Timeline of Events
Initial analysis by NIST: 11/09/2023
Third-party advisory by Patchstack: 05/14/2024
CVSS V3.1 added by Patchstack: 11/21/2024
CVE modification by CISA-ADP: 2/26/2025
Mitigation and Solutions
Users are advised to update their Advanced Page Visit Counter plugin to the latest version (8.0.1 or higher) to mitigate this vulnerability. It is also essential to secure WordPress sites with strong passwords, regularly update plugins, and use reliable security solutions.
Looking Forward
As cyber threats continue to evolve, it is crucial for WordPress users to stay vigilant and proactive in securing their websites. This incident serves as a reminder of the importance of keeping software up-to-date and following best security practices.