Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.127075
Category:Web application abuses
Title:WordPress WP Statistics Plugin <= 12.6.6 SQLi Vulnerability
Summary:The WordPress plugin 'WP Statistics' is prone to an SQL injection; (SQLi) vulnerability.
Description:Summary:
The WordPress plugin 'WP Statistics' is prone to an SQL injection
(SQLi) vulnerability.

Vulnerability Insight:
An endpoint of the API, which is exposed when the
'use cache plugin' setting is enabled (by default disabled), is vulnerable to an unauthenticated
blind SQLi issue.

Affected Software/OS:
WordPress WP Statistics plugin version 12.6.6 and prior.

Solution:
Update to version 12.6.7 or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-13275
https://github.com/wp-statistics/wp-statistics/commit/bd46721b97794a1b1520e24ff5023b6da738dd75
https://wordpress.org/plugins/wp-statistics/#developers
https://wpvulndb.com/vulnerabilities/9412
CopyrightCopyright (C) 2022 Greenbone Networks GmbH

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.