← Back to browse · API

CVE-2022-0513

Severity
CRITICAL
CVSS
9.8
EPSS
0.5346
Risk score
57.91
CISA KEV
No
PoC
No
Published
2022-02-16
Modified
2025-02-10
First seen
2026-08-07
Aliases
EUVD-2022-15641, GHSA-6GR9-X8M9-C46V
Products
VeronaLabs:WP Statistics 13.1.4 ≤13.1.4
Sources
euvd EUVD-2022-15641

Description

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.4. This requires the "Record Exclusions" option to be enabled on the vulnerable site.

References