vendor:
Advanced Page Visit Counter
by:
Furkan ÖZER
6.1
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Advanced Page Visit Counter
Affected Version From: 1
Affected Version To: 8.0.5
Patch Exists: NO
Related CWE:
CPE: a:wordpress:advanced_page_visit_counter:1.0
Platforms Tested: Kali-Linux, Windows 10, Windows 11
2023
Advanced Page Visit Counter 1.0 – Admin+ Stored Cross-Site Scripting (XSS) (Authenticated)
The Advanced Page Visit Counter plugin for WordPress, up to version 8.0.5, is vulnerable to a Stored Cross-Site Scripting (XSS) attack. This vulnerability allows authenticated users, including administrators, to inject malicious scripts into the plugin's settings, potentially leading to the execution of arbitrary code in the context of other users' sessions.
Mitigation:
To mitigate this vulnerability, users should update to a patched version of the Advanced Page Visit Counter plugin. Additionally, users are advised to validate and sanitize user inputs to prevent XSS attacks.