CVE-2023-0955

WP Statistics < 14.0 - Authenticated SQLi

The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.


We have discovered 22,858 live websites that are affected by CVE-2023-0955.

Run a Free Instant Scan




Affected Software

Product  WP Statistics
Category Wordpress Plugins
Vulnerable Domains22,858 live websites (19% of WP Statistics install base)
Vulnerable Versions
  • from 0 through 14
Vulnerable Versions Count59 versions ( 43% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Mar 27, 2023
  • Updated - Feb 19, 2025

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2023-0955
United States3,366 websites



Germany3,979 websites
France1,938 websites
Japan1,453 websites
Italy1,032 websites
Iran966 websites
Poland861 websites
Netherlands723 websites
Russia668 websites
Vietnam550 websites

Website Distribution by TLD

Number of websites using CVE-2023-0955
.com7,670 websites
.de2,573 websites
.org966 websites
.fr915 websites
.net691 websites
.it669 websites
.pl644 websites
.nl593 websites
.ru503 websites
.eu350 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-0955

Top websites that are affected by CVE-2023-0955. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
***********.fr France**,***
*********.com United States**,***
**********************.com United States**,***
***************.com Germany**,***
*****.ru Russia**,***
*******.net United States**,***
***.**.th Thailand**,***
****************.eu Switzerland***,***
*******.tk United States***,***
See full domain list

FAQ

CVE-2023-0955 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in WP Statistics
A total of 22,858 websites have been identified as vulnerable to CVE-2023-0955, based on global website indexing conducted by WebTechSurvey.
The WP Statistics is affected by the CVE-2023-0955 vulnerability.
WP Statistics versions up to 14 are vulnerable to CVE-2023-0955.
CVE-2023-0955 is resolved in version 14 of WP Statistics.