CVE Feed

    Dashboard / CVE / CVE-2015-5533

    CVE-2015-5533

    SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

    Published:Oct 23, 2017
    Last Modified:Apr 20, 2025
    EPS:Oct 23, 2017
    EPSS Score:0.09524
    CVSS Score:7.2

    Affected Products

    Vendor
    Count Per Day Project
    Product
    Count Per Day

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High