PT-2022-17100 · WordPress · Wp Statistics

Muhammad Zeeshan

·

Published

2022-02-24

·

Updated

2022-03-03

·

CVE-2022-25149

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP Statistics versions up to and including 13.1.5
Description The issue is related to SQL Injection due to insufficient escaping and parameterization of the IP parameter in the ~/includes/class-wp-statistics-hits.php file. This allows attackers without authentication to inject arbitrary SQL queries and obtain sensitive information.
Recommendations For versions up to and including 13.1.5, update to a version later than 13.1.5 to resolve the issue. As a temporary workaround, consider restricting access to the ~/includes/class-wp-statistics-hits.php file to minimize the risk of exploitation. Avoid using the IP parameter in the affected functionality until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25149

Affected Products

Wp Statistics