📦 Wp Statistics

by Veronalabs

🔍 What is Wp Statistics?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-38074

CRITICAL CVSS 9.9 Mar 13, 2023

CVE-2022-38074 is a SQL injection vulnerability in the VeronaLabs WP Statistics WordPress plugin that allows authenticated attackers to execute arbitrary SQL commands. This affects WordPress sites run...

CVE-2022-25148

CRITICAL CVSS 9.8 Feb 24, 2022

This SQL injection vulnerability in the WP Statistics WordPress plugin allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can extract sensitive information from the database,...

CVE-2022-0651

CRITICAL CVSS 9.8 Feb 24, 2022

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites running the WP Statistics plugin. Attackers can extract sensitive database information including...

CVE-2022-0513

CRITICAL CVSS 9.8 Feb 16, 2022

This vulnerability allows unauthenticated attackers to perform SQL injection attacks on WordPress sites running the WP Statistics plugin with 'Record Exclusions' enabled. Attackers can extract sensiti...

CVE-2023-0955

HIGH CVSS 8.8 Mar 27, 2023

This SQL injection vulnerability in the WP Statistics WordPress plugin allows authenticated users to execute arbitrary SQL commands. By default, only administrators can exploit it, but the plugin's se...

CVE-2022-25305

HIGH CVSS 7.2 Feb 24, 2022

This vulnerability allows attackers to inject malicious scripts into the WP Statistics WordPress plugin's IP parameter. When site administrators view statistics pages, these scripts execute in their b...

CVE-2022-25307

HIGH CVSS 7.2 Feb 24, 2022

This vulnerability allows attackers to inject malicious scripts into the WP Statistics WordPress plugin's platform parameter. When site administrators view statistics pages, these scripts execute in t...

CVE-2021-24340

HIGH CVSS 7.5 Jun 7, 2021

This vulnerability in the WP Statistics WordPress plugin allows SQL injection attacks due to improper query preparation and insufficient input sanitization. The affected administrative page was also a...