WP Statistics < 14.0 - Authenticated SQLi
CVE-2023-0955
8.8HIGH
Summary
The WP Statistics plugin for WordPress, prior to version 14.0, has a vulnerability that allows authenticated users to exploit unsanitized input parameters to execute SQL Injection attacks. Although the feature is primarily accessible to users with administrative privileges (manage_options capability), settings within the plugin permit lower-privileged users to access it, thereby expanding the attack surface. This vulnerability emphasizes the importance of validating and sanitizing user inputs to prevent unauthorized data manipulation.
Affected Version(s)
WP Statistics 0 < 14.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Erwan LR (WPScan)
WPScan