CVE-2022-25148

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
CVSS

No CVSS.

Configurations

No configuration.

Information

Published : 2022-02-24 19:15

Updated : 2022-02-25 12:57


NVD link : CVE-2022-25148

Mitre link : CVE-2022-25148


JSON object : View

Products Affected

No product.

CWE

No CWE.