CVE-2022-38074: WordPress WP Statistics Plugin <= 13.2.10 is vulnerable to SQL Injection
Published Mar 13, 2023
·Updated
SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.
Affected Software
1 affected component
VeronaLabs Wp Statistics Wordpress<13.2.11
Remediation
Information
Update to 13.2.11 or a higher version.
Event History
Mar 13, 2023
CVE Published
via MITRE·01:43 PM
Data Sourced
via MITRE·01:43 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-38074?
CVE-2022-38074 is classified as a critical SQL Injection vulnerability affecting the WP Statistics plugin.
2
How do I fix CVE-2022-38074?
To fix CVE-2022-38074, update the WP Statistics plugin to version 13.2.11 or later.
3
What are the potential risks of CVE-2022-38074?
Exploitation of CVE-2022-38074 can lead to unauthorized access and modification of database information.
4
Which versions of the WP Statistics plugin are affected by CVE-2022-38074?
CVE-2022-38074 affects WP Statistics plugin versions 13.2.10 and earlier.
5
Is CVE-2022-38074 targetable by unauthenticated users?
CVE-2022-38074 can potentially be exploited by authenticated users with low-level permissions.