First published: Thu Jul 04 2019(Updated: )
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WP Statistics | <=12.6.6 |
https://github.com/wp-statistics/wp-statistics/commit/bd46721b97794a1b1520e24ff5023b6da738dd75
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-13275 is considered critical due to the potential for unauthenticated blind SQL Injection.
To fix CVE-2019-13275, upgrade the wp-statistics plugin to version 12.6.7 or later.
CVE-2019-13275 affects versions of the wp-statistics plugin prior to 12.6.7.
Yes, CVE-2019-13275 can be exploited without authentication, allowing attackers to perform SQL injection.
The impact of CVE-2019-13275 may include unauthorized access to your database and extraction of sensitive information.