logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-25148

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-25148

Description:
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
Last updated date:
01/25/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
03/03/2022
Reference url to background

https://gist.github.com/Xib3rR4dAr/5dbd58b7f57a5037fe461fba8e696042

Type:
exploit
Confidence:
HIGH
Date of publishing:
01/25/2024
Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy