Aller au contenu

Fiche vulnérabilité

CVE-2022-25149 : faille élevée veronalabs wp statistics (CVSS 7.5)

Description

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
24 févr. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • veronalabs wp statistics

Références

Rechercher une autre vulnérabilité dans la base CVE