What the vulnerability does
01Description
SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
What the vulnerability does
SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.
Explanation of Vulnerability in Simple Terms
WP Statistics versions up to 13.2.10 contain a SQL injection vulnerability in a component accessible to authenticated users. An attacker with low-level site access can craft malicious input to read sensitive data from the database, including user information and site configuration. The vulnerability does not allow data modification or site takeover, but exposes confidential information.
What an attacker can do
Read sensitive data from the site database, including user records and configuration details.
Potential impact on your site
User data and site configuration may be exposed to any authenticated user, even those with minimal permissions.
Conditions required to exploit
Attacker must have a low-level user account (subscriber or contributor role) on the WordPress site.
Key dates
External resources
Related vulnerabilities