Vulnerability record · CVE-2022-0513 · published 16 February 2022
CVE-2022-0513: WP Statistics plugin unauthenticated SQL injection via exclusion_reason
Veronalabs · Wp Statistics
The WP Statistics WordPress plugin fails to escape and parameterize the exclusion_reason parameter in includes/class-wp-statistics-exclusion.php, allowing unauthenticated SQL injection in versions up to and including 13.1.4. Exploitation requires the site's "Record Exclusions" option to be enabled, which limits exposure but leaves affected sites open to database data theft.
Description
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the exclusion_reason parameter found in the ~/includes/class-wp-statistics-exclusion.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.4. This requires the "Record Exclusions" option to be enabled on the vulnerable site.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable SQL injection with high confidentiality impact and a high EPSS score, though exploitation is conditional on the "Record Exclusions" setting being enabled.
What it is
The WP Statistics WordPress plugin fails to escape and parameterize the exclusion_reason parameter in includes/class-wp-statistics-exclusion.php, allowing unauthenticated SQL injection in versions up to and including 13.1.4. Exploitation requires the site's "Record Exclusions" option to be enabled, which limits exposure but leaves affected sites open to database data theft.
Impact
An unauthenticated attacker can inject arbitrary SQL queries and read sensitive information from the WordPress database, such as user credentials and other stored data. The CVSS vector shows high confidentiality impact with no integrity or availability impact.
Attack surface
Reachable over the network through the vulnerable plugin endpoint handling the exclusion_reason parameter; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The only precondition stated is that the "Record Exclusions" option must be enabled on the target site.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.5346 (98.9th percentile) and a public Wordfence advisory tagged "Exploit" exists, indicating public exploit knowledge. No ransomware usage is documented.
What to do
- Update WP Statistics to a version newer than 13.1.4, which contains the patch referenced in the plugin changeset.
- If patching cannot be done immediately, disable the "Record Exclusions" option to remove the vulnerable code path.
- Apply a web application firewall rule or virtual patch blocking SQL injection attempts against the exclusion_reason parameter.
- Review whether the plugin is still needed and remove or deactivate it if not in active use.
Detection
- Search web server and WAF logs for requests containing SQL syntax or encoded payloads in the exclusion_reason parameter.
- Monitor database query logs for unexpected SELECT statements or UNION patterns originating from the WordPress application.
- Check plugin configuration to identify sites with "Record Exclusions" enabled and prioritize them for patching.
- Review WordPress audit or access logs for anomalous unauthenticated requests to WP Statistics endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://plugins.trac.wordpress.org/changeset/2671297/wp-statistics/trunk/includes/class-wp-statistics-hits.php | PatchThird Party Advisory |
| https://www.wordfence.com/blog/2022/02/unauthenticated-sql-injection-vulnerability-patched-in-wordpress-statistics-plugi | ExploitPatchThird Party Advisory |
| https://plugins.trac.wordpress.org/changeset/2671297/wp-statistics/trunk/includes/class-wp-statistics-hits.php | PatchThird Party Advisory |
| https://www.wordfence.com/blog/2022/02/unauthenticated-sql-injection-vulnerability-patched-in-wordpress-statistics-plugi | ExploitPatchThird Party Advisory |
Track CVE-2022-0513 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-0513), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.