S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Mar 4, 2024

CVE-2022-0651 Scanner

CVE-2022-0651 scanner - SQL Injection vulnerability in WordPress WP Statistics Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0651
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WP Statisticsby WP Statistics
13.1.5
Updated Aug 22, 2026View on NVD →
Detail

WP Statistics is a powerful WordPress plugin developed by VeronaLabs, designed for gathering and analyzing website statistics. It offers comprehensive insights into site visits, visitor locations, page views, and search engine referrals. This plugin is widely utilized by WordPress site owners to monitor traffic patterns, optimize content, and enhance user engagement. Its ease of use and detailed reporting capabilities make it an essential tool for website analytics.

The vulnerability stems from the plugin's inadequate sanitization and parameterization of user inputs, specifically within the current_page_type parameter in the ~/includes/class-wp-statistics-hits.php file. By crafting malicious requests to the WP Statistics REST API, attackers can manipulate SQL queries executed by the plugin. This issue exposes the website to various SQL Injection attacks, highlighting the need for strict input validation and the use of prepared statements in database operations.

Exploiting this vulnerability could allow attackers to access sensitive data stored in the WordPress database, including user credentials, personal information, and website content. Additionally, attackers could leverage this flaw to modify or delete data, disrupt website operations, and potentially gain unauthorized administrative access. The severity of the impact underscores the critical need for immediate remediation measures.

By subscribing to the S4E platform, users gain access to advanced security scanning solutions that can detect vulnerabilities like CVE-2022-0651 in the WP Statistics plugin. Our service provides detailed vulnerability assessments, real-time monitoring, and actionable recommendations to enhance your cybersecurity posture. Membership benefits include prioritized remediation guidance, support from security experts, and comprehensive tools to protect your digital assets from emerging threats.

 

References

Solution Advice
  1. Urgently update the WP Statistics plugin to version 13.1.6 or the latest version available.
  2. Regularly update all WordPress plugins and themes to their newest versions to mitigate known vulnerabilities.
  3. Implement website security best practices, including the use of web application firewalls (WAFs) and secure coding standards.
  4. Conduct periodic security audits and vulnerability assessments to identify and address potential security gaps.
  5. Educate website administrators and users on the importance of security awareness and the risks associated with SQL Injection attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-0651 scanner - SQL Injection vulnerability in WordPress WP Statistics Plugin | S4E