CVE-2022-25149: WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via IP
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-25149?
CVE-2022-25149 has a medium severity rating due to its potential for SQL Injection, allowing unauthorized access to the database.
How do I fix CVE-2022-25149?
To fix CVE-2022-25149, update the WP Statistics plugin to the latest version released after 13.1.5.
Who is affected by CVE-2022-25149?
CVE-2022-25149 affects users of the WP Statistics plugin versions up to and including 13.1.5.
Can CVE-2022-25149 be exploited remotely?
Yes, CVE-2022-25149 can be exploited remotely by attackers without requiring authentication.
What can attackers achieve with CVE-2022-25149?
Attackers can use CVE-2022-25149 to inject arbitrary SQL queries, potentially leading to data theft or manipulation.