CVE-2022-38074

WordPress WP Statistics Plugin <= 13.2.10 is vulnerable to SQL Injection

SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.


We have discovered 37,576 live websites that are affected by CVE-2022-38074.

Test my site




Affected Software

Product  WP Statistics
Category Wordpress Plugins
Vulnerable Domains37,576 live websites (21.03% of WP Statistics install base)
Vulnerable Versions
  • from 0 through 13.2.10
Vulnerable Versions Count62 versions ( 50.00% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Mar 13, 2023
  • Updated - Jan 8, 2025

Credits

  • Rafie Muhammad (Patchstack) (finder)

CVE-2022-38074 usage by Country

United States6,766 websites



Germany6,900 websites
France3,399 websites
Japan2,162 websites
Iran2,133 websites
Poland1,414 websites
Netherlands1,083 websites
Russia992 websites
Vietnam934 websites
GB793 websites

CVE-2022-38074 usage by TLD

.com13,071 websites
.de3,887 websites
.org1,526 websites
.fr1,426 websites
.net1,140 websites
.pl1,105 websites
.nl940 websites
.ru761 websites
.ch589 websites
.it560 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-38074

Top websites that are affected by CVE-2022-38074. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
***********.fr France**,***
******.pl Poland**,***
*********.com United States**,***
**********************.com United States**,***
***************.com Poland**,***
***.**.th Thailand**,***
*******.tk United States***,***
******.*******.pl Poland***,***
**********.com United States***,***
See full domain list

FAQ

CVE-2022-38074 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in WP Statistics
A total of 37,576 websites have been identified as vulnerable to CVE-2022-38074, discovered through global website indexing conducted by WebTechSurvey.
WP Statistics is susceptible to CVE-2022-38074 vulnerability.
WP Statistics versions before, and including, 13.2.10 are vulnerable to CVE-2022-38074.