7.5
CVSSv3

CVE-2022-0513

Published: 16/02/2022 Updated: 24/02/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.4. This requires the "Record Exclusions" option to be enabled on the vulnerable site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

veronalabs wp statistics

Exploits

WordPress VeronaLabs WP Statistics plugin versions 1314 and suffer from a remote unauthenticated blind SQL injection vulnerability ...