Product
The WP Visitor Statistics plugin (up to 8.7) is vulnerable to a second-order SQL injection allowing unauthenticated attackers to exfiltrate database information via the 'fullRef' parameter.