S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24340 Scanner

CVE-2021-24340 scanner - SQL Injection (SQLi) vulnerability in WP Statistics plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24340
7.5
CVSS

The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been accessible to administrator only, was also available to any visitor, including unauthenticated ones.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WP Statisticsby VeronaLabs
AFFECTED< 13.0.8SAFE ✓≥ 13.0.8
Updated Aug 21, 2026View on NVD →
Detail

WP Statistics plugin for WordPress is a popular analytics tool used by website administrators to keep track of their website's traffic. This plugin allows users to monitor the number of visitors, page views, and referrals their website receives. It also enables users to monitor any changes in their website's traffic patterns and helps them make informed decisions about their website's future.

The CVE-2021-24340 vulnerability was detected in the WP Statistics plugin for WordPress. This vulnerability occurred due to the reliance on the WordPress esc_sql() function on a field that was not delimited by quotes, and the query was not prepared before use. Additionally, the page, which should have only been accessible to administrators, was available to every visitor, including unauthenticated users.

When exploited, this vulnerability could lead to attackers gaining unauthorized access to sensitive information. An attacker could use this vulnerability to execute arbitrary SQL queries on the targeted website's database. This could result in a complete compromise of the website's database, including personal information, login credentials, and transaction data. The attacker could also use this vulnerability to modify or delete data from the database, leading to a loss of data integrity.

Those who read this article can easily and quickly learn about vulnerabilities in their digital assets through the pro features of the s4e.io platform. With this platform, website administrators can perform vulnerability scans and receive reports on any vulnerabilities detected on their website. This can help them stay on top of any potential security risks and ensure the safety of their website and customers' data.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website administrators can follow these precautions:

  • Update the WP Statistics plugin to the latest version
  • Limit access to the wp-admin page only to authorized users
  • Implement additional security measures, such as two-factor authentication, to protect against unauthorized access
  • Monitor their website's traffic patterns and look out for any suspicious activity
  • Regularly perform backups to ensure that they can quickly recover data in the event of a compromise

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-24340 scanner - SQL Injection (SQLi) vulnerability in WP Statistics plugin for WordPress S4E