Lucene search

K
patchstackMuhammad Zeeshan (Xib3rR4dAr)PATCHSTACK:49C069436ED3D6156B0EC09F0167A85B
HistoryFeb 16, 2022 - 12:00 a.m.

WordPress WP Statistics plugin <= 13.1.5 - Unauthenticated Blind SQL Injection (SQLi) vulnerability

2022-02-1600:00:00
Muhammad Zeeshan (Xib3rR4dAr)
patchstack.com
23
wordpress
wp statistics
unauthenticated
blind sql injection
sqli
current_page_id
muhammad zeeshan
xib3rr4dar
update
version 13.1.6

EPSS

0.619

Percentile

97.9%

Unauthenticated Blind SQL Injection (SQLi) vulnerability via current_page_id discovered by Muhammad Zeeshan (Xib3rR4dAr) in WordPress WP Statistics plugin (versions <= 13.1.5).

Solution

           Update the WordPress WP Statistics plugin to the latest available version (at least 13.1.6).

EPSS

0.619

Percentile

97.9%