S4E just found a high-severity finding from [ai] web application login panel detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2015-4062 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in NewStatPress plugin for WordPress affects v. before 0.9.9.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2015-4062
6.5
CVSS

SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

The NewStatPress plugin for WordPress is a tool for website owners to monitor and analyze the visitors to their sites. This plugin allows users to track metrics, including the number of visitors, page views, and search queries performed on their site. With NewStatPress, website owners can gather insights to help optimize their content and marketing efforts.

In June 2015, a vulnerability was detected in the NewStatPress plugin, known as CVE-2015-4062. This vulnerability allowed remote authenticated users to execute arbitrary SQL commands, using the "where1" parameter in the "nsp_search" page to the "wp-admin/admin.php" file. This vulnerability affected versions of NewStatPress up to and including version 0.9.8.9.

When exploited, the CVE-2015-4062 vulnerability could lead to significant security risks and consequences. Attackers could use this vulnerability to obtain unauthorized access to a website's database, gain privileged information or sensitive data, or even execute arbitrary code on the server. Such an attack could have grave implications for the security, confidentiality, and integrity of a website and its users.

At s4e.io, our pro features provide a comprehensive and reliable overview of vulnerabilities in your digital assets. With our platform, users can easily and quickly learn about vulnerabilities and threats to their website's security. Our security experts use the latest tools and technologies to uncover potential risks and provide actionable recommendations to prevent attacks and minimize damage in case of a breach. By taking advantage of our pro features, website owners can stay one step ahead of cybercriminals and protect their reputation, business, and customers.

 

REFERENCES

Solution Advice

To protect against the CVE-2015-4062 vulnerability, users should take the following precautions:

  • Ensure that the NewStatPress plugin is updated to the latest version (0.9.9 or higher).
  • If the plugin is no longer in use, it should be removed completely from the website.
  • Use a web application firewall (WAF) to monitor and block any attempts at SQL injection attacks.
  • Limit access to the wp-admin directory to only those who need it and enforce strong passwords for all users.
  • Regularly backup website data and ensure that all systems are up-to-date and secure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2015-4062 scanner - SQL Injection (SQLi) vulnerability in NewStatPress plugin for WordPress | S4E