WP Statistics < 14.0 - Authenticated SQLi
CVE-2023-0955

8.8HIGH

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
27 March 2023

Summary

The WP Statistics plugin for WordPress, prior to version 14.0, has a vulnerability that allows authenticated users to exploit unsanitized input parameters to execute SQL Injection attacks. Although the feature is primarily accessible to users with administrative privileges (manage_options capability), settings within the plugin permit lower-privileged users to access it, thereby expanding the attack surface. This vulnerability emphasizes the importance of validating and sanitizing user inputs to prevent unauthorized data manipulation.

Affected Version(s)

WP Statistics 0 < 14.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Erwan LR (WPScan)
WPScan
.