WP Statistics SQL Injection vulnerability

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Security experts at Sucuri have discovered a SQL Injection vulnerability in WP Statistics, one of the most popular WordPress plugins, that is currently installed on over 300,000 websites. The SQL Injection vulnerability in WP Statistics could be exploited by attackers, with at least a subscriber account, to access the content of the database and potentially take over the vulnerable websites remotely. The flaw has been discovered in the highly popular WP Statistics plugin, which allows site administrators to get detailed information related to the number of users online on their sites, the number of visits and visitors, and page statistics. “This vulnerability is caused by the lack of sanitization in user provided data. An attacker with at least a subscriber account could leak sensitive data and under the right circumstances/configurations compromise your WordPress installation.” reads the analysis published by Sucuri. “If you have a vulnerable version installed and your site allows...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息