Loading HuntDB...

GHSA-wg9m-p2x3-fg97

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

Related CVEs

Key Information

GHSA ID
GHSA-wg9m-p2x3-fg97
Published
February 25, 2022 12:00 AM
Last Modified
September 5, 2023 6:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 28, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.