Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12940 | The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well. |
Wed, 19 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-19T20:04:49.536Z
Reserved: 2023-02-22T14:48:07.477Z
Link: CVE-2023-0955
Updated: 2024-08-02T05:32:46.204Z
Status : Modified
Published: 2023-03-27T16:15:09.387
Modified: 2025-02-19T20:15:34.453
Link: CVE-2023-0955
No data.
OpenCVE Enrichment
No data.
No weakness.
EUVD