CVE-2023-45001
WordPress Seriously Simple Stats plugin <= 1.5.0 - SQL Injection vulnerability
CVSS Score
8.5
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability in Craig Hewitt Seriously Simple Stats seriously-simple-stats.This issue affects Seriously Simple Stats: from n/a through <= 1.5.0.
| CWE | CWE-89 |
| Vendor | craig hewitt |
| Product | seriously simple stats |
| Published | Nov 6, 2023 |
| Last Updated | Apr 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for craig hewitt seriously simple stats
Be the first to know when new high vulnerabilities affecting craig hewitt seriously simple stats are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
Low
Affected Versions
Craig Hewitt / Seriously Simple Stats
0 โค 1.5.0
References
patchstack.com: https://patchstack.com/database/Wordpress/Plugin/seriously-simple-stats/vulnerability/wordpress-seriously-simple-stats-plugin-1-5-0-sql-injection-vulnerability?_s_id=cve patchstack.com: https://patchstack.com/database/vulnerability/seriously-simple-stats/wordpress-seriously-simple-stats-plugin-1-5-0-sql-injection-vulnerability?_s_id=cve
Credits
Rafie Muhammad | Patchstack Bug Bounty Program