CVE-2022-38074


WordPress WP Statistics Plugin <= 13.2.10 is vulnerable to SQL Injection

SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.



We have discovered 14,244 live websites that are affected by CVE-2022-38074.

Contact us to get more info




Affected Software

Product  WP Statistics
Category Wordpress Plugins
Vulnerable Versions
  • from 0 through 13.2.10
Total Vulnerable Versions83
Vulnerable Domains14,244 live websites (7.86% of WP Statistics install base)


Common Weakness Enumeration


CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-38074 and the relative popularity of websites


Details

  • Published - Mar 13, 2023
  • Updated - Mar 13, 2023

Credits

  • Rafie Muhammad (Patchstack) (finder)





Countries

United States1,977 websites



Germany2,846 websites
France1,037 websites
Iran769 websites
Japan652 websites
Netherlands528 websites
Italy524 websites
Poland499 websites
GB375 websites
Spain349 websites

TLDs

.com4,457 websites
.de1,965 websites
.org735 websites
.fr459 websites
.nl404 websites
.net396 websites
.pl370 websites
.it336 websites
.ch225 websites
.at224 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-38074 through included software libraries and plugins.



References


Websites affected by CVE-2022-38074

Top websites that are affected by CVE-2022-38074. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
********.com United States*,***
************.***.in India**,***
***.***********.fr France**,***
*************.***.ua Ukraine**,***
*****.*******.*********.com United States**,***
***.************.com United States**,***
***.***********.com United States**,***
***.***********.at Austria**,***
***.**********.**.il Israel**,***
**.******.org Netherlands**,***
See full domain list