Input validation vulnerability in WP Statistics 9.4.1

The WP Statistics plugin for WordPress is vulnerable to a security issue called blind SQL Injection. This means that someone with administrative access can use the plugin to extract sensitive information from the database. This was possible in versions of the plugin before 9.4.1 due to the way it escaped user supplied parameters and prepared existing SQL queries.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.