Input validation vulnerability in WP Statistics 13.1.5

The WP Statistics WordPress plugin is not secure in versions up to and including 13.1.5. Attackers who do not need to be authenticated can use an unsafe method to inject SQL queries that can give them access to sensitive information. This method involves manipulating the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.