The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.4. This requires the "Record Exclusions" option to be enabled on the vulnerable site.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Wordfence

Published: 2022-02-16T16:38:03

Updated: 2022-02-16T16:38:03

Reserved: 2022-02-07T00:00:00


Link: CVE-2022-0513

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-02-16T17:15:11.503

Modified: 2022-02-24T19:33:08.360


Link: CVE-2022-0513

JSON object: View

cve-icon Redhat Information

No data.

CWE