WordPress · Post Views Stats Counter · CVE-2026-97347
**Name of the Vulnerable Software and Affected Versions**
Post Views Stats Counter versions prior to 1.1.8
**Description**
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Unauthenticated attackers can inject arbitrary web scripts through the User-Agent header. These scripts execute when a user accesses an affected page. The current input filter uses a substring blacklist for bot signatures such as `bot`, `spider`, and `crawler`, which can be bypassed by crafting a payload that avoids these specific strings.
**Recommendations**
Update Post Views Stats Counter to version 1.1.8 or later.