CVE-2022-4230


WP Statistics < 13.2.9 - Authenticated SQLi

The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.



We have discovered 13,313 live websites that are affected by CVE-2022-4230.

Contact us to get more info




Affected Software

Product  WP Statistics
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 13.2.9
Total Vulnerable Versions83
Vulnerable Domains13,313 live websites (7.35% of WP Statistics install base)


Common Weakness Enumeration


CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2022-4230 and the relative popularity of websites


Details

  • Published - Jan 23, 2023

Credits

  • Jordy Versmissen (finder)
  • WPScan (coordinator)





Countries

United States1,823 websites



Germany2,705 websites
France987 websites
Iran697 websites
Japan610 websites
Italy493 websites
Netherlands477 websites
Poland460 websites
GB353 websites
Spain324 websites

TLDs

.com4,120 websites
.de1,874 websites
.org696 websites
.fr446 websites
.net364 websites
.nl364 websites
.pl346 websites
.it319 websites
.at208 websites
.eu203 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2022-4230 through included software libraries and plugins.



References


Websites affected by CVE-2022-4230

Top websites that are affected by CVE-2022-4230. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
********.com United States*,***
************.***.in India**,***
***.***********.fr France**,***
*************.***.ua Ukraine**,***
*****.*******.*********.com United States**,***
***.************.com United States**,***
***.***********.com United States**,***
***.***********.at Austria**,***
***.**********.**.il Israel**,***
**.******.org Netherlands**,***
See full domain list