CVE · High

CVE-2021-24340 — WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.0.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24340 WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.0.8 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 13.0.8 13.0.8 2021-05-19

CVE-2021-24340

The WP Statistics plugin versions prior to 13.0.8 contained a SQL injection vulnerability because it applied the esc_sql() function to an unquoted database field without properly preparing the underlying query. Additionally, a sensitive administrative page lacked proper access controls and could be accessed by any visitor, including those without authentication.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.