Vulnerability Bulletins

Over 600,000 Sites Impacted by WP Statistics Patch

   
Affected software Wordpress
 
On March 13, 2021, the Wordfence Threat Intelligence team initiated responsible disclosure for a vulnerability in WP Statistics, a plugin installed on over 600,000 WordPress sites. The vulnerability allowed any site visitor to extract sensitive information from a site’s database via Time-Based Blind SQL Injection. We received a response to our initial disclosure the same […]

More info:

https://www.wordfence.com/blog/2021/05/over-600000-sites-impacted-by-wp-statistics-patch/