Skip to content

Known CVE

WordPress NewStatPress 0.9.8 - SQL Injection

WordPress NewStatPress 0.9.8 plugin contains a SQL injection vulnerability in includes/nsp_search.php. A remote authenticated user can execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.

CVE-2015-4062

Medium2015CVSS 6.5CWE-89

time-based-sqli · cve2015 · authenticated · sqli · wp-plugin · newstatpress · packetstorm · wordpress

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website