CVE-2023-0955: WP Statistics < 14.0 - Authenticated SQLi
The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manageoptions capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0955?
CVE-2023-0955 has a medium severity rating due to its potential to allow SQL Injection attacks.
How do I fix CVE-2023-0955?
To fix CVE-2023-0955, update the WP Statistics plugin to version 14.0 or later.
Who is affected by CVE-2023-0955?
CVE-2023-0955 affects users of the WP Statistics WordPress plugin versions prior to 14.0.
What capability gives access to the vulnerable feature in CVE-2023-0955?
The vulnerable feature in CVE-2023-0955 is accessible to users with the manage_options capability, typically administrators.
Can unauthenticated users exploit CVE-2023-0955?
No, CVE-2023-0955 can only be exploited by authenticated users with admin-like privileges.