9.8
CVSSv3

CVE-2022-25148

Published: 24/02/2022 Updated: 25/01/2024
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

veronalabs wp statistics

Exploits

WordPress WP Statistics plugin version 1315 suffers from a remote SQL injection vulnerability ...