CVE-2021-24340 is a critical blind SQL injection vulnerability affecting the WP Statistics WordPress plugin prior to version 13.0.8. This flaw allowed unauthenticated attackers to exploit improper SQL sanitization and access an administrator-only page, leading to potential data exfiltration. With a CVSS score of 7.5 (High) and an EPSS score indicating significant exploitability, it presents a severe risk due to its low attack complexity and high impact on confidentiality. While not listed in CISA's KEV catalog, public Nuclei templates exist for exploitation, and it has garnered community discussion and media coverage, suggesting awareness among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0.8, < 13.0.8CPE match | cpe:2.3:a:veronalabs:wp_statistics:*:*:*:*:*:wordpress:*:* | ||
< 13.0.8CPE matchmatch criteria | cpe:2.3:a:veronalabs:wp_statistics:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.