← Back to browse · API

CVE-2022-25149

Severity
CRITICAL
CVSS
9.8
EPSS
0.77956
Risk score
66.48
CISA KEV
No
PoC
No
Published
2022-02-24
Modified
2025-01-31
First seen
2026-08-07
Aliases
EUVD-2022-29892, GHSA-GMJF-VVGP-P553
Products
VeronaLabs:WP Statistics 13.1.5 ≤13.1.5
Sources
euvd EUVD-2022-29892

Description

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

References