The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
Advisories
No advisories yet.
Fixes
Solution
Update to version 13.1.6 or newer.
Workaround
No workaround given by the vendor.
References
History
Fri, 31 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-01-31T18:55:15.260Z
Reserved: 2022-02-14T00:00:00.000Z
Link: CVE-2022-25149
Updated: 2024-08-03T04:29:01.770Z
Status : Modified
Published: 2022-02-24T19:15:10.453
Modified: 2024-11-21T06:51:41.860
Link: CVE-2022-25149
No data.
OpenCVE Enrichment
No data.
Weaknesses