Veronalabs
Veronalabs WP Statistics: vulnerabilidades y CVE
Veronalabs WP Statistics tiene 21 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses1
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-48839 | Alta (7.1) | 0.25% | — | 1 jun 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. This issue affects WP Statistics: from n/a through 14.16.6. |
| CVE-2025-55716 | Media (4.3) | 0.20% | — | 14 ago 2025 | Missing Authorization vulnerability in VeronaLabs WP Statistics wp-statistics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Statistics: from n/a through <= 14.15. |
| CVE-2023-0955 | Alta (8.8) | 0.90% | — | 27 mar 2023 | The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the… |
| CVE-2022-38074 | Alta (8.8) | 0.73% | — | 13 mar 2023 | SQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions. |
| CVE-2021-4333 | Media (6.5) | 0.38% | — | 7 mar 2023 | The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing or incorrect nonce validation on the view() function. This makes it… |
| CVE-2022-4230 | Alta (8.8) | 36% | — | 23 ene 2023 | The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the… |
| CVE-2022-27231 | Media (6.1) | 1.0% | — | 13 jun 2022 | Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a platform parameter. By exploiting this vulnerability, an arbitrary script may be executed on the web… |
| CVE-2022-1005 | Media (6.1) | 0.89% | — | 8 jun 2022 | The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back in the rendered page, leading to Cross-Site Scripting (XSS) in web browsers which do not encode… |
| CVE-2022-25307 | Media (6.1) | 1.4% | — | 24 feb 2022 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the platform parameter found in the ~/includes/class-wp-statistics-hits.php file which allows… |
| CVE-2022-25306 | Media (6.1) | 1.4% | — | 24 feb 2022 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the browser parameter found in the ~/includes/class-wp-statistics-visitor.php file which allows… |
| CVE-2022-25305 | Media (6.1) | 79% | — | 24 feb 2022 | The WP Statistics WordPress plugin is vulnerable to Cross-Site Scripting due to insufficient escaping and sanitization of the IP parameter found in the ~/includes/class-wp-statistics-ip.php file which allows attackers… |
| CVE-2022-25149 | Alta (7.5) | 77% | — | 24 feb 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the IP parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers… |
| CVE-2022-25148 | Alta (7.5) | 81% | — | 24 feb 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows… |
| CVE-2022-0651 | Alta (7.5) | 32% | — | 24 feb 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which… |
| CVE-2022-0513 | Alta (7.5) | 53% | — | 16 feb 2022 | The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which… |
| CVE-2021-24340 | Alta (7.5) | 30% | — | 7 jun 2021 | The WP Statistics WordPress plugin before 13.0.8 relied on using the WordPress esc_sql() function on a field not delimited by quotes and did not first prepare the query. Additionally, the page, which should have been… |
| CVE-2017-18515 | Crítica (9.8) | 2.5% | — | 14 ago 2019 | The wp-statistics plugin before 12.0.8 for WordPress has SQL injection. |
| CVE-2019-13275 | Crítica (9.8) | 2.6% | — | 4 jul 2019 | An issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use cache plugin" setting is enabled, is vulnerable to unauthenticated… |
| CVE-2019-12566 | Media (5.4) | 1.1% | — | 3 jun 2019 | The WP Statistics plugin through 12.6.5 for Wordpress has stored XSS in includes/class-wp-statistics-pages.php. This is related to an account with the Editor role creating a post with a title that contains JavaScript,… |
| CVE-2019-10864 | Media (6.1) | 1.4% | — | 23 abr 2019 | The WP Statistics plugin through 12.6.2 for WordPress has XSS, allowing a remote attacker to inject arbitrary web script or HTML via the Referer header of a GET request. |
| CVE-2018-1000556 | Media (6.1) | 0.71% | — | 26 jun 2018 | WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.