Security readout for executives and security teams
Plain-English summary
CVE-2019-13275 affects the WordPress wp-statistics plugin before 12.6.7. If the non-default “use cache plugin” setting is enabled, a public API hit-tracking endpoint can be vulnerable to unauthenticated blind SQL injection. The main business concern is database exposure on affected WordPress sites.
Executive priority
Treat as high priority for affected public WordPress sites. The vulnerable configuration is conditional, so first determine whether the plugin and setting are present, then upgrade or disable the risky setting promptly.
Technical view
The reported flaw is in the wp-statistics v1/hit API endpoint before version 12.6.7. The vulnerable condition depends on the “use cache plugin” setting being enabled. Sources describe unauthenticated blind SQL injection, but provide no CVSS, CWE, or confirmed exploitation evidence in the supplied bundle.
Likely exposure
Exposure is limited to WordPress sites running wp-statistics before 12.6.7 with the non-default cache-plugin integration setting enabled. Internet-facing WordPress sites are the practical concern because the affected endpoint is an API endpoint reachable without authentication.
Exploitation context
The bundle does not show CISA KEV listing or cited evidence of active exploitation. The vulnerability is still serious because it is unauthenticated and SQL-injection related, but exploitation evidence and impact details are incomplete in the supplied sources.
Researcher notes
The supplied data identifies product, vulnerable version range, endpoint, configuration dependency, and fix reference, but lacks CVSS, CWE, exploit telemetry, and detailed impact analysis. Avoid assuming broader wp-statistics versions or WordPress components beyond the described plugin flaw.
Mitigation direction
- Upgrade wp-statistics to version 12.6.7 or later.
- Disable the “use cache plugin” setting if immediate upgrade is delayed.
- Review vendor release notes and the referenced fixing commit.
- Prioritize internet-facing WordPress sites using the affected plugin.
- Monitor WordPress and web application logs for unusual API activity.
Validation and detection
- Inventory WordPress sites using the wp-statistics plugin.
- Confirm installed wp-statistics versions are 12.6.7 or later.
- Check whether the “use cache plugin” setting is enabled.
- Review exposure of the wp-statistics v1/hit API endpoint.
- Confirm no forked or pinned plugin copy remains vulnerable.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Database behavior lookup
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2019-13275 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://wordpress.org/plugins/wp-statistics/#developersCVE reference · x_refsource_MISC
- https://github.com/wp-statistics/wp-statistics/commit/bd46721b97794a1b1520e24ff5023b6da738dd75CVE reference · x_refsource_MISC
- https://wpvulndb.com/vulnerabilities/9412CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
