S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-25149 Scanner

CVE-2022-25149 scanner - SQL Injection vulnerability in WordPress Plugin WP Statistics

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-25149
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WP Statisticsby WP Statistics
13.1.5
Updated Aug 22, 2026View on NVD →
Detail

WP Statistics is a popular analytics plugin for WordPress, designed by VeronaLabs. It enables website owners to track and analyze their website traffic directly from the WordPress dashboard without relying on external services. This plugin provides detailed statistics on visitor counts, geographical locations, page views, and referral sources. It's particularly favored by website administrators for its ease of use and comprehensive data visualization tools. WP Statistics is widely used across various types of websites, from small personal blogs to large business sites, to improve SEO strategies and enhance user engagement.

The WP Statistics plugin versions up to and including 13.1.5 are susceptible to a SQL Injection vulnerability due to improper sanitization and parameterization of the IP parameter in the ~/includes/class-wp-statistics-hits.php file. This flaw allows unauthenticated attackers to inject and execute arbitrary SQL commands. Such vulnerabilities are critical as they can lead to unauthorized access to sensitive information, database manipulation, or disclosure of confidential data.

This specific vulnerability is triggered by manipulating the IP parameter in requests sent to the WP Statistics plugin. The lack of adequate input validation enables attackers to craft malicious SQL queries that the server will execute. As a result, attackers can retrieve sensitive data from the database, such as user information, without needing any authentication. This exploitation can occur through simple web requests, making it a severe threat to websites using vulnerable versions of the plugin.

The exploitation of this SQL Injection vulnerability can lead to several adverse effects, including unauthorized access to sensitive database information, alteration or deletion of data, and potential website compromise. It could also result in the exposure of personal data of the website's users, undermining the privacy and security of the affected site. The breach could damage the website's reputation, lead to loss of trust among users, and potentially have legal implications for data protection violations.

Joining S4E provides you with the tools and resources to identify vulnerabilities like the SQL Injection in WP Statistics promptly. Our platform offers detailed scans, insights into the severity of detected vulnerabilities, and actionable remediation advice. Members benefit from continuous monitoring and updates on the latest cybersecurity threats, ensuring your website remains secure against evolving threats. With S4E, you can safeguard your digital presence, protect your users' data, and maintain your website's integrity.

 

References

Solution Advice
  1. Immediately update the WP Statistics plugin to version 13.1.6 or later to address the SQL Injection vulnerability.
  2. Regularly check and update all WordPress plugins and themes to their latest versions to ensure security patches are applied.
  3. Utilize web application firewalls (WAFs) and security plugins to detect and prevent SQL Injection and other common web attacks.
  4. Conduct regular security audits of your WordPress site to identify and mitigate potential vulnerabilities.
  5. Educate yourself and your team on secure coding practices and the importance of validating and sanitizing user inputs.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-25149 scanner - SQL Injection vulnerability in WordPress Plugin WP Statistics | S4E