VendorsVeronaLabswp_statisticsall versions
Vulnerabilities

VeronaLabs WP Statistics

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2022-25148
WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via current_page_id
Published 2022-02-24 · Modified
9.81 PoCEPSS 0.809
CVE-2022-25149
WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via IP
Published 2022-02-24 · Modified
9.8EPSS 0.775
CVE-2022-0513
WP Statistics <= 13.1.4 Unauthenticated Blind SQL Injection via exclusion_reason
Published 2022-02-16 · Modified
9.8EPSS 0.535
CVE-2022-0651
WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via current_page_type
Published 2022-02-24 · Modified
9.8EPSS 0.322
CVE-2019-13275
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.
Published 2019-07-04 · Modified
9.8EPSS 0.026
CVE-2017-18515
The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.
Published 2019-08-14 · Modified
9.8EPSS 0.025
CVE-2022-4230
WP Statistics < 13.2.9 - Authenticated SQLi
Published 2023-01-23 · Modified
8.8EPSS 0.357
CVE-2023-0955
WP Statistics < 14.0 - Authenticated SQLi
Published 2023-03-27 · Modified
8.8EPSS 0.009
CVE-2022-38074
WordPress WP Statistics Plugin <= 13.2.10 is vulnerable to SQL Injection
Published 2023-03-13 · Modified
8.8EPSS 0.007
CVE-2021-24340
WP Statistics < 13.0.8 - Unauthenticated SQL Injection
Published 2021-06-07 · Modified
7.5EPSS 0.298
CVE-2022-25305
WP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via IP
Published 2022-02-24 · Modified
7.2EPSS 0.789
CVE-2022-25306
WP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via browser
Published 2022-02-24 · Modified
7.2EPSS 0.014
CVE-2022-25307
WP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via platform
Published 2022-02-24 · Modified
7.2EPSS 0.014
CVE-2021-4333
WP Statistics <= 13.1.1 - Cross-Site Request Forgery to Arbitrary Plugin Activation and Deactivation
Published 2023-03-07 · Modified
6.5EPSS 0.004
CVE-2019-10864
The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request.
Published 2019-04-23 · Modified
6.1EPSS 0.014
CVE-2022-27231
Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web browser of the user who is logging in to the website using the product.
Published 2022-06-13 · Modified
6.1EPSS 0.010
CVE-2022-1005
WP Statistics < 13.2.2 - Reflected Cross-Site Scripting
Published 2022-06-06 · Modified
6.1EPSS 0.009
CVE-2018-1000556
WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing a cookie to code injection. This attack appear to be exploitable via an attacker must craft an URL with payload and send to the user. Victim need to open the link to be affected by reflected XSS. .
Published 2018-06-26 · Modified
6.1EPSS 0.007
CVE-2019-12566
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript, to attack an admin user.
Published 2019-06-02 · Modified
5.4EPSS 0.011