← Vulnerability feed

Vulnerability record · CVE-2022-0513 · published 16 February 2022

CVE-2022-0513: WP Statistics plugin unauthenticated SQL injection via exclusion_reason

Veronalabs · Wp Statistics

The WP Statistics WordPress plugin fails to escape and parameterize the exclusion_reason parameter in includes/class-wp-statistics-exclusion.php, allowing unauthenticated SQL injection in versions up to and including 13.1.4. Exploitation requires the site's "Record Exclusions" option to be enabled, which limits exposure but leaves affected sites open to database data theft.

7.5 CVSS 3.1 High EPSS 53% · top 1.0% CWE-89 · SQL injection
7.5CVSS 3.1 base score, v2 4.3
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.4. This requires the "Record Exclusions" option to be enabled on the vulnerable site.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityUnauthenticated network-reachable SQL injection with high confidentiality impact and a high EPSS score, though exploitation is conditional on the "Record Exclusions" setting being enabled.

What it is

The WP Statistics WordPress plugin fails to escape and parameterize the exclusion_reason parameter in includes/class-wp-statistics-exclusion.php, allowing unauthenticated SQL injection in versions up to and including 13.1.4. Exploitation requires the site's "Record Exclusions" option to be enabled, which limits exposure but leaves affected sites open to database data theft.

Impact

An unauthenticated attacker can inject arbitrary SQL queries and read sensitive information from the WordPress database, such as user credentials and other stored data. The CVSS vector shows high confidentiality impact with no integrity or availability impact.

Attack surface

Reachable over the network through the vulnerable plugin endpoint handling the exclusion_reason parameter; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The only precondition stated is that the "Record Exclusions" option must be enabled on the target site.

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.5346 (98.9th percentile) and a public Wordfence advisory tagged "Exploit" exists, indicating public exploit knowledge. No ransomware usage is documented.

What to do

  • Update WP Statistics to a version newer than 13.1.4, which contains the patch referenced in the plugin changeset.
  • If patching cannot be done immediately, disable the "Record Exclusions" option to remove the vulnerable code path.
  • Apply a web application firewall rule or virtual patch blocking SQL injection attempts against the exclusion_reason parameter.
  • Review whether the plugin is still needed and remove or deactivate it if not in active use.

Detection

  • Search web server and WAF logs for requests containing SQL syntax or encoded payloads in the exclusion_reason parameter.
  • Monitor database query logs for unexpected SELECT statements or UNION patterns originating from the WordPress application.
  • Check plugin configuration to identify sites with "Record Exclusions" enabled and prioritize them for patching.
  • Review WordPress audit or access logs for anomalous unauthenticated requests to WP Statistics endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-0513 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-25148WP Statistics plugin unauthenticated SQL injection via current_page_idThe WP Statistics WordPress plugin fails to escape and parameterize the current_page_id parameter in includes/class-wp-statistics-hits.php, allowing …EPSS 81%analysed9.8CVE-2017-18515Veronalabs wp statistics sql injection vulnerabilityThe wp-statistics plugin before 12.0.8 for WordPress has SQL injection.EPSS 2.5%9.8CVE-2019-13275Veronalabs wp statistics sql injection vulnerabilityAn issue was discovered in the VeronaLabs wp-statistics plugin before 12.6.7 for WordPress. The v1/hit endpoint of the API, when the non-default "use…EPSS 2.6%8.8CVE-2023-0955Veronalabs wp statistics vulnerabilityThe WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. B…EPSS 0.90%8.8CVE-2022-38074Veronalabs wp statistics sql injection vulnerabilitySQL Injection vulnerability in VeronaLabs WP Statistics plugin <= 13.2.10 versions.EPSS 0.73%8.8CVE-2022-4230Veronalabs wp statistics sql injection vulnerabilityThe WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks.…EPSS 36%7.5CVE-2022-25149WP Statistics plugin unauthenticated SQL injection via IP parameterThe WP Statistics WordPress plugin fails to escape and parameterize the IP parameter in includes/class-wp-statistics-hits.php, allowing unauthenticat…EPSS 77%analysed7.5CVE-2022-0651Veronalabs wp statistics sql injection vulnerabilityThe WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type paramete…EPSS 32%

Source: NIST National Vulnerability Database (record CVE-2022-0513), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.