Vulnerability record · CVE-2022-25148 · published 24 February 2022
CVE-2022-25148: WP Statistics plugin unauthenticated SQL injection via current_page_id
Veronalabs · Wp Statistics
The WP Statistics WordPress plugin fails to escape and parameterize the current_page_id parameter in includes/class-wp-statistics-hits.php, allowing unauthenticated SQL injection in versions up to and including 13.1.5. Because the flaw is reachable without credentials and can read or alter database contents, it is a serious risk to any site running an affected version.
Description
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and very high EPSS make this an urgent patch-first issue.
What it is
The WP Statistics WordPress plugin fails to escape and parameterize the current_page_id parameter in includes/class-wp-statistics-hits.php, allowing unauthenticated SQL injection in versions up to and including 13.1.5. Because the flaw is reachable without credentials and can read or alter database contents, it is a serious risk to any site running an affected version.
Impact
An attacker can inject arbitrary SQL to obtain sensitive information from the WordPress database, and the CVSS vector also indicates potential integrity and availability impact.
Attack surface
Reachable over the network through the plugin's hits handling code with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.8093, 99.6th percentile) and public exploit references exist, indicating active interest and likely weaponization.
What to do
- Update WP Statistics to a version newer than 13.1.5, which contains the fix referenced in the plugin changeset.
- If immediate patching is not possible, disable or remove the WP Statistics plugin until it can be updated.
- Deploy a WAF rule blocking SQL injection patterns against the current_page_id parameter and plugin endpoints.
- Audit the WordPress database and logs for signs of unauthorized SQL access or data exfiltration.
- Restrict database account privileges used by WordPress to the minimum required.
Detection
- Monitor web server and WAF logs for SQL injection payloads targeting current_page_id or WP Statistics endpoints.
- Look for anomalous database queries or errors originating from the plugin's hits handling code.
- Review access logs for unauthenticated requests to WP Statistics paths with suspicious parameter values.
- Check for unexpected changes to database contents or new administrative users that could indicate post-exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/174482/WordPress-WP-Statistics-13.1.5-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://gist.github.com/Xib3rR4dAr/5dbd58b7f57a5037fe461fba8e696042 | ExploitThird Party Advisory |
| https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2679983%40wp-statistics&new=2679983%40w | PatchThird Party Advisory |
| https://www.wordfence.com/vulnerability-advisories/#CVE-2022-25148 | Third Party Advisory |
| http://packetstormsecurity.com/files/174482/WordPress-WP-Statistics-13.1.5-SQL-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://gist.github.com/Xib3rR4dAr/5dbd58b7f57a5037fe461fba8e696042 | ExploitThird Party Advisory |
| https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=2679983%40wp-statistics&new=2679983%40w | PatchThird Party Advisory |
| https://www.wordfence.com/vulnerability-advisories/#CVE-2022-25148 | Third Party Advisory |
Track CVE-2022-25148 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-25148), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.