vendor:
WP Statistics
by:
Mansoor R (@time4ster)
7.5
CVSS
HIGH
Time-Based Blind SQL Injection
89
CWE
Product Name: WP Statistics
Affected Version From: 13.0
Affected Version To: 13.0.7
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:wp-statistics
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: wp-statistics 13.0.6,13.0.7
2021
WordPress Plugin WP Statistics 13.0.7 – Time-Based Blind SQL Injection (Unauthenticated)
WordPress Plugin WP Statistics 13.0.7 is vulnerable to Time-Based Blind SQL Injection (Unauthenticated). An attacker can exploit this vulnerability to gain access to the database of the website. The vulnerability exists due to insufficient sanitization of user-supplied input in the 'ID' parameter of the 'wp-admin/admin.php' page. An attacker can send a specially crafted request to the vulnerable page and inject malicious SQL queries to gain access to the database. The vulnerability affects versions 13.0 to 13.0.7 of the plugin. The patch for this vulnerability is available in version 13.0.8 of the plugin.
Mitigation:
Upgrade to wp-statistics 13.0.8 (or above)