PT-2026-103101 · WordPress · Post Views Stats Counter

·

CVE-2026-97347

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Post Views Stats Counter versions prior to 1.1.8
Description Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Unauthenticated attackers can inject arbitrary web scripts through the User-Agent header. These scripts execute when a user accesses an affected page. The current input filter uses a substring blacklist for bot signatures such as bot, spider, and crawler, which can be bypassed by crafting a payload that avoids these specific strings.
Recommendations Update Post Views Stats Counter to version 1.1.8 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97347

Affected Products

Post Views Stats Counter