CVE-2019-13275: SQL Injection
Published Jul 4, 2019
·Updated
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated blind SQL Injection.
Affected Software
1 affected component
VeronaLabs Wp Statistics Wordpress<=12.6.6
Remediation
Event History
Jul 4, 2019
CVE Published
via MITRE·06:51 PM
Data Sourced
via MITRE·06:51 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13275?
CVE-2019-13275 is considered critical due to the potential for unauthenticated blind SQL Injection.
2
How do I fix CVE-2019-13275?
To fix CVE-2019-13275, upgrade the wp-statistics plugin to version 12.6.7 or later.
3
What versions of wp-statistics are affected by CVE-2019-13275?
CVE-2019-13275 affects versions of the wp-statistics plugin prior to 12.6.7.
4
Can CVE-2019-13275 be exploited without authentication?
Yes, CVE-2019-13275 can be exploited without authentication, allowing attackers to perform SQL injection.
5
What is the impact of CVE-2019-13275 on my WordPress website?
The impact of CVE-2019-13275 may include unauthorized access to your database and extraction of sensitive information.