Blog | G5 Cyber Security

SQL Injection flaw in WordPress Plugin WP Statistics potentially exposed 300,000+ Sites

Security experts at Sucuri have discovered a vulnerability in the popular WP Statistics plugin. The plugin allows admin users to get detailed information related to the number of users online on their sites. The vulnerability is caused by the lack of sanitization in user provided data. An attacker with at least a subscriber account could leak sensitive data and under the right circumstances/configurations could take over the vulnerable websites remotely. The flaw has been discovered in the highly popular plugin that is currently installed on over 300,000 websites.”]

Source: http://securityaffairs.co/wordpress/60596/hacking/wordpress-wp-statistics-flaw.html

Exit mobile version