CVE-2023-0955

WP Statistics < 14.0 - Authenticated SQLi

The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.


We have discovered 41,249 live websites that are affected by CVE-2023-0955.

Test my site




Affected Software

Product  WP Statistics
Category Wordpress Plugins
Vulnerable Domains41,249 live websites (23.09% of WP Statistics install base)
Vulnerable Versions
  • from 0 before 14
Vulnerable Versions Count68 versions ( 54.84% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Mar 27, 2023
  • Updated - Feb 19, 2025

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)

CVE-2023-0955 usage by Country

United States8,025 websites



Germany7,609 websites
France3,618 websites
Iran2,275 websites
Japan2,269 websites
Poland1,533 websites
Netherlands1,180 websites
Russia1,061 websites
Vietnam975 websites
GB854 websites

CVE-2023-0955 usage by TLD

.com14,495 websites
.de4,330 websites
.org1,693 websites
.fr1,660 websites
.net1,239 websites
.pl1,201 websites
.nl1,039 websites
.ru818 websites
.ch619 websites
.it601 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2023-0955

Top websites that are affected by CVE-2023-0955. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
***********.fr France**,***
******.pl Poland**,***
*********.com United States**,***
**********************.com United States**,***
***************.com Poland**,***
*****.ru Russia**,***
***.**.th Thailand**,***
****************.eu Switzerland***,***
*******.tk United States***,***
See full domain list

FAQ

CVE-2023-0955 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in WP Statistics
A total of 41,249 websites have been identified as vulnerable to CVE-2023-0955, discovered through global website indexing conducted by WebTechSurvey.
WP Statistics is susceptible to CVE-2023-0955 vulnerability.
WP Statistics versions before 14 are vulnerable to CVE-2023-0955.
Version 14 of WP Statistics addresses the CVE-2023-0955 security vulnerability.