CVE · High

CVE-2022-25149 — WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-25149 WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 13.1.6 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.5 < 13.1.6 13.1.6 2022-02-16

CVE-2022-25149

The WP Statistics plugin contained a SQL injection vulnerability in its hits tracking functionality that allowed unauthenticated attackers to execute malicious SQL commands by manipulating the IP parameter. The flaw stemmed from inadequate escaping and parameterization of user input within the class-wp-statistics-hits.php file. Attackers could exploit this vulnerability to extract sensitive data from the database. The issue affected all versions through 13.1.5 and was resolved in version 13.1.6.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.