CVE Database /
CVE-2022-25149
CVE · High
CVE-2022-25149 — WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-25149
|
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6 |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') |
High
7.5
|
< 13.1.6
|
13.1.6 |
2022-02-16 |
—
|
CVE-2022-25149
The WP Statistics plugin contained a SQL injection vulnerability in its hits tracking functionality that allowed unauthenticated attackers to execute malicious SQL commands by manipulating the IP parameter. The flaw stemmed from inadequate escaping and parameterization of user input within the class-wp-statistics-hits.php file. Attackers could exploit this vulnerability to extract sensitive data from the database. The issue affected all versions through 13.1.5 and was resolved in version 13.1.6.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings