The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.
We have discovered 41,249 live websites that are affected by CVE-2023-0955.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 41,249 live websites (23.09% of WP Statistics install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 68 versions ( 54.84% of all versions) |
![]() | 8,025 websites |
![]() | 7,609 websites |
![]() | 3,618 websites |
![]() | 2,275 websites |
![]() | 2,269 websites |
![]() | 1,533 websites |
![]() | 1,180 websites |
![]() | 1,061 websites |
![]() | 975 websites |
![]() | 854 websites |
.com | 14,495 websites |
.de | 4,330 websites |
.org | 1,693 websites |
.fr | 1,660 websites |
.net | 1,239 websites |
.pl | 1,201 websites |
.nl | 1,039 websites |
.ru | 818 websites |
.ch | 619 websites |
.it | 601 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
********.com | ![]() | *,*** | |
***********.fr | ![]() | **,*** | |
******.pl | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
**********************.com | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
*****.ru | ![]() | **,*** | |
***.**.th | ![]() | **,*** | |
****************.eu | ![]() | ***,*** | |
*******.tk | ![]() | ***,*** |
FAQ