CVE-2023-0955


WP Statistics < 14.0 - Authenticated SQLi

The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.



We have discovered 20,339 live websites that are affected by CVE-2023-0955.

Contact us to get more info




Affected Software

Product  WP Statistics
Category Wordpress Plugins
Vulnerable Versions
  • from 0 before 14
Total Vulnerable Versions83
Vulnerable Domains20,339 live websites (11.23% of WP Statistics install base)


Common Weakness Enumeration


CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2023-0955 and the relative popularity of websites


Details

  • Published - Mar 27, 2023
  • Updated - Mar 27, 2023

Credits

  • Erwan LR (WPScan) (finder)
  • WPScan (coordinator)





Countries

United States3,234 websites



Germany4,029 websites
France1,637 websites
Iran1,066 websites
Japan837 websites
Poland776 websites
Netherlands731 websites
Italy725 websites
GB519 websites
Spain467 websites

TLDs

.com6,526 websites
.de2,832 websites
.org996 websites
.fr814 websites
.pl578 websites
.nl578 websites
.net559 websites
.it471 websites
.eu294 websites
.at293 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2023-0955 through included software libraries and plugins.



References


Websites affected by CVE-2023-0955

Top websites that are affected by CVE-2023-0955. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
********.com United States*,***
************.***.in India**,***
***.***********.fr France**,***
****.org Australia**,***
*************.***.ua Ukraine**,***
*****.*******.*********.com United States**,***
***.************.com United States**,***
***.***********.com United States**,***
***.***********.at Austria**,***
***.**********.**.il Israel**,***
See full domain list