rootpwn

high · CVSS v3 7.2 · EPSS 0.00254

CVE-2026-97347

The Post Views Stats Counter plugin for WordPress is vulnerable to stored XSS via the User-Agent header in all versions up to 1.1.7. Unauthe

Overview

The Post Views Stats Counter plugin for WordPress is vulnerable to stored XSS via the User-Agent header in all versions up to 1.1.7. Unauthenticated attackers can inject malicious scripts that execute when users view any page served by the plugin, enabling defacement, credential theft, or malware distribution.

Description

The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin's only input filter is a substring blacklist for known bot signatures (e.g. 'bot', 'spider', 'crawler'), which can be trivially bypassed by crafting a User-Agent payload that omits those strings.

Impact

Confidentiality: injected scripts can exfiltrate user data or credentials. Integrity: malicious code can alter page content or inject hidden links. Availability: repeated exploitation may degrade site performance or overwhelm resources. Site administrators and WordPress users are directly impacted.

Remediation

Update the plugin to the latest version (1.1.8 or later) or uninstall it if not needed. If an update is unavailable, configure a web application firewall to block or sanitize User-Agent headers, or add a custom filter to escape output before rendering. Monitor server logs for suspicious User-Agent strings and apply rate limiting on requests containing unusual headers.

Risk context

The vulnerability has a high severity rating (CVSS 7.2) but a low EPSS score (0.00254), indicating it is serious yet not widely exploited. Defenders should prioritize patching within the next 30 days to mitigate potential attacks.

Affected products

  • WordPress Post Views Stats Counter

Scores

Severity
high
CVSS v2
6.4
CVSS v3
7.2
CVSS v4
—
EPSS
0.00254

wordpress xss stored-xss user-agent plugin wp-security

← All CVEs