CVE · Medium

CVE-2021-4333 — WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-4333 WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.2 Cross-Site Request Forgery (CSRF) Medium 6.5 < 13.1.2 13.1.2 2021-09-11

CVE-2021-4333

The WP Statistics plugin for WordPress up to version 13.1.1 contains a Cross-Site Request Forgery vulnerability in the view() function due to insufficient nonce verification. An unauthenticated attacker could exploit this flaw to enable or disable arbitrary plugins if they can deceive a site administrator into clicking a malicious link. The vulnerability was resolved in version 13.1.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.