SQL Injection Vulnerability in Count Per Day Plugin for WordPress
CVE-2015-5533
What is CVE-2015-5533?
The Count Per Day plugin for WordPress prior to version 3.4.1 contains an SQL injection vulnerability in the counter-options.php file. This issue allows remote authenticated administrators to send specially crafted requests to the wp-admin/options-general.php endpoint, specifically through the cpd_keep_month parameter. Exploitations can lead to arbitrary SQL command execution, potentially compromising the integrity of the database. Moreover, this vulnerability can be exploited in conjunction with CSRF attacks, allowing remote attackers to execute malicious SQL commands under certain conditions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
9% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved