Wp Statistics vulnerabilities

9 known vulnerabilities affecting wp_statistics/wp_statistics.

Total CVEs
9
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2022-25149HIGHCVSS 7.5PoC≥ 13.1.5, ≤ 13.1.52022-02-24
CVE-2022-25149 [HIGH] CWE-89 CVE-2022-25149: The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and p The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
cvelistv5nvd
CVE-2022-25148HIGHCVSS 7.5PoC≥ 13.1.5, ≤ 13.1.52022-02-24
CVE-2022-25148 [HIGH] CWE-89 CVE-2022-25148: The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and p The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1
cvelistv5nvd
CVE-2022-0651HIGHCVSS 7.5PoC≥ 13.1.5, ≤ 13.1.52022-02-24
CVE-2022-0651 [HIGH] CWE-89 CVE-2022-0651: The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and p The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1
cvelistv5nvd
CVE-2022-25305MEDIUMCVSS 6.1≥ 13.1.5, ≤ 13.1.52022-02-24
CVE-2022-25305 [MEDIUM] CWE-79 CVE-2022-25305: The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escapin The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions up to an
cvelistv5nvd
CVE-2022-25306MEDIUMCVSS 6.1≥ 13.1.5, ≤ 13.1.52022-02-24
CVE-2022-25306 [MEDIUM] CWE-79 CVE-2022-25306: The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escapin The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in version
cvelistv5nvd
CVE-2022-25307MEDIUMCVSS 6.1≥ 13.1.5, ≤ 13.1.52022-02-24
CVE-2022-25307 [MEDIUM] CWE-79 CVE-2022-25307: The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escapin The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers to inject arbitrary web scripts onto several pages that execute when site administrators view a sites statistics, in versions
cvelistv5nvd
CVE-2017-2136MEDIUMCVSS 6.1≤ 12.0.4vversion 12.0.4 and earlier2017-04-28
CVE-2017-2136 [MEDIUM] CWE-79 CVE-2017-2136: Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attacke Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.
cvelistv5nvd
CVE-2017-2147MEDIUMCVSS 6.1vversion 12.0.4 and earlier2017-04-28
CVE-2017-2147 [MEDIUM] CWE-79 CVE-2017-2147: Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attacke Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
cvelistv5nvd
CVE-2017-2135MEDIUMCVSS 6.1vversion 12.0.1 and earlier2017-04-28
CVE-2017-2135 [MEDIUM] CWE-79 CVE-2017-2135: Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attacke Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
cvelistv5nvd