WP Statistics
wp-statistics · eklenti
WP Statistics için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
23 bilinen açık
3 kritik · 4 kayıt için istismar kodu yayımlanmış · son kayıt 30 Eyl 2026
Güvenlik açıkları
- Kritik 9.8
WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via current_page_id
- Kritik 9.8
The wp-statistics plugin before 12.0.8 for WordPress has SQL injection.
- Kritik 9.8
An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress.
- Yüksek 8.8
WordPress WP Statistics Plugin <= 13.2.10 is vulnerable to SQL Injection
- Yüksek 7.5
WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via IP
- Yüksek 7.5
WP Statistics <= 13.1.5 Unauthenticated Blind SQL Injection via current_page_type
- Yüksek 7.5
WP Statistics <= 13.1.4 Unauthenticated Blind SQL Injection via exclusion_reason
- Yüksek 7.2
WP Statistics <= 14.16.8 - Unauthenticated Stored Cross-Site Scripting via 'utm_campaign' Parameter
- Yüksek 7.2
WP Statistics <= 14.16.4 - Unauthenticated Stored Cross-Site Scripting via 'utm_source' Parameter
- Yüksek 7.2
WP Statistics <= 14.5.4 - Unauthenticated Stored Cross-Site Scripting via User-Agent Header
- Yüksek 7.2
WP Statistics <= 14.5 - Unauthenticated Stored Cross-Site Scripting
- Yüksek 7.1
WordPress WP Statistics plugin <= 14.16.13 - Cross Site Scripting (XSS) vulnerability
- Yüksek 7.1
WordPress WP Statistics plugin <= 14.16.6 - Cross Site Scripting (XSS) vulnerability
- Orta 6.5
WP Statistics <= 14.16.4 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure and Privacy Audit Manipulation
- Orta 6.5
WP Statistics <= 13.1.1 - Cross-Site Request Forgery to Arbitrary Plugin Activation and Deactivation
- Orta 6.1
WordPress WP Statistics plugin <= 14.16.11 - Cross Site Scripting (XSS) vulnerability
- Orta 6.1
Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter.
- Orta 6.1
WP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via platform
- Orta 6.1
WP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via browser
- Orta 6.1
WP Statistics <= 13.1.5 Unauthenticated Stored Cross-Site Scripting via IP
- Orta 5.4
WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin <= 14.13.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings U
- Orta 5.4
The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php.
- Orta 4.3
WordPress WP Statistics Plugin <= 14.15 - Broken Access Control Vulnerability