CVEFinder.io

CVE-2021-4333

πŸ”Ά medium
πŸ” Scan for this CVE
Summary

The WP Statistics plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 13.1.1. This is due to missing or incorrect nonce validation on the view() function. This makes it possible for unauthenticated attackers to activate and deactivate arbitrary plugins, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVSS Score
6.5
Medium
EPSS Score
0.1
Exploit Probability
Published Date
2023-03-07
First Seen: 2026-01-05
πŸ“Š Relative Risk Intelligence

This CVE is Lower Risk - more severe than 47.8% of all 313,973 vulnerabilities in our database.

#163,850
Below average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Jan 13, 2025
πŸ” Exploitation Status
None
No known exploits
βš™οΈ Automatable
NO
Requires human interaction
πŸ’₯ Technical Impact
Partial
Limited system impact
πŸ† Discovered By
Ramuel Gall
SSVC data provided by CISA
Last Modified 2024-11-21
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

πŸ“¦ Affected Products 1

πŸ”— References 2

πŸ”— Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2025-55716 πŸ”Ά medium - 0.0 Missing Authorization vulnerability in VeronaLabs WP Statistics wp-statistics allows Exploiting Incorrectly Configured A... 2025-08-14
CVE-2023-0955 ⚠️ high 8.8 0.7 The WP Statistics WordPress plugin before 14.0 does not escape a parameter, which could allow authenticated users to per... 2023-03-27
CVE-2022-38074 β›” critical 9.9 0.5 SQL Injection vulnerability in VeronaLabs WP Statistics pluginΒ <= 13.2.10 versions. 2023-03-13
CVE-2022-4230 ⚠️ high 8.8 9.3 The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to p... 2023-01-23
CVE-2022-27231 πŸ”Ά medium 6.1 0.3 Cross-site scripting vulnerability exists in WP Statistics versions prior to 13.2.0 because it improperly processes a pl... 2022-06-13
CVE-2022-1005 πŸ”Ά medium 6.1 0.3 The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter before outputting it back i... 2022-06-08
These CVEs affect the same products