Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-0651 PoC — WordPress plugin WP Statistics SQL注入漏洞

Source
Associated Vulnerability
Title:WordPress plugin WP Statistics SQL注入漏洞 (CVE-2022-0651)
Description:WordPress是Wordpress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是WordPress开源的一个应用插件。 WordPress plugin WP Statistics 存在SQL注入漏洞,攻击者可利用该漏洞在没有身份验证的情况下注入任意SQL查询以获取敏感信息。
Description
The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.
File Snapshot

id: CVE-2022-0651 info: name: WordPress Plugin WP Statistics <= 13.1.5 - SQL Injection author: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.