The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-02T15:35:05.010Z
Reserved: 2022-11-30T10:37:40.491Z
Link: CVE-2022-4230
Updated: 2024-08-03T01:34:49.929Z
Status : Modified
Published: 2023-01-23T15:15:14.133
Modified: 2025-04-02T16:15:23.893
Link: CVE-2022-4230
No data.
OpenCVE Enrichment
No data.
Weaknesses