WP Statistics; Attention WordPress fans , as a vulnerability allowing SQL Injection has been discovered in one of the platform's most popular plugins. The plugin is installed on over 300,000 websites, which could be compromised by hackers to steal databases and potentially manage them remotely.
The flaw has been discovered in the very popular WP Statistics plugin, which allows website administrators using the WordPress CMS to have detailed information about the number of visitors to their page and other statistics.
Discovered by the Sucuri security team:
The WordPress plugin, WP Statistics, is vulnerable to a flaw that allows SQL Injection. A remote attacker, who would need to have at least one subscriber account, could steal sensitive information from the page's database and potentially gain unauthorized access to it.
SQL Injection is a bug that allows hackers to inject malicious SQL code into the target page to determine the structure and location of the database, which ultimately allows the database to be stolen.
The SQL injection vulnerability in the WP Statistics plugin is found in many of its functions, such as wp_statistics_searchengine_query().
“This vulnerability is due to the lack of security of user-provided data,” the researchers said. “Some attributes of the wpstatistics shortcode are passed as parameters to important functions and there should be no problem if they are overridden.”
“One of the vulnerable functions is wp_statistics_searchengine_query() in the file 'includes/functions/functions.php' which is accessible via WordPress' AJAX functionality thanks to the core function wp_ajax_parse_media_shortcode().”
This feature does not check for additional permissions, which allows site subscribers to execute as a shortcode and insert malicious code into its features.
Sucuri researchers discovered the flaw in the WP Statistics team and reported it to the plugin developers. The development team was able to patch the vulnerability with the latest version of WP Statistics 12.0.8.
So, if you are using an older version of the plugin installed on your website and allowing user registration, you are at risk and should upgrade to the latest version as soon as possible.
