vendor:
WP Statistics Plugin
by:
psychoSherlock
7.5
CVSS
HIGH
Time based SQL injection
89
CWE
Product Name: WP Statistics Plugin
Affected Version From: 13.1.2005
Affected Version To: 13.1.2005
Patch Exists: YES
Related CWE: CVE-2022-25148
CPE: a:wp-statistics:wp-statistics:13.1.5
Platforms Tested:
2022
WP Statistics Plugin <= 13.1.5 current_page_id - Time based SQL injection (Unauthenticated)
This exploit targets the WP Statistics Plugin version 13.1.5 and prior. It allows an unauthenticated attacker to perform a time-based SQL injection attack by manipulating the 'current_page_id' parameter in the '/wp-json/wp-statistics/v2/hit' endpoint. The vulnerability can be exploited to cause a delay in the response time of the target server, indicating a successful injection.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update to WP Statistics Plugin version 13.1.6 or later to mitigate the risk of exploitation. It is also recommended to restrict access to the affected endpoint to trusted users only.