The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update to version 13.1.6 or newer.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2024-08-03T04:29:01.616Z
Reserved: 2022-02-14T00:00:00
Link: CVE-2022-25148
No data.
Status : Modified
Published: 2022-02-24T19:15:10.400
Modified: 2024-11-21T06:51:41.747
Link: CVE-2022-25148
No data.
OpenCVE Enrichment
No data.
Weaknesses