PT-2026-103101 · WordPress · Post Views Stats Counter
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Post Views Stats Counter versions prior to 1.1.8
Description
Stored Cross-Site Scripting occurs due to insufficient input sanitization and output escaping. Unauthenticated attackers can inject arbitrary web scripts through the User-Agent header. These scripts execute when a user accesses an affected page. The current input filter uses a substring blacklist for bot signatures such as
bot, spider, and crawler, which can be bypassed by crafting a payload that avoids these specific strings.Recommendations
Update Post Views Stats Counter to version 1.1.8 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Post Views Stats Counter