vendor:
Advanced Page Visit Counter
by:
Furkan ÖZER
6.1
CVSS
HIGH
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: Advanced Page Visit Counter
Affected Version From: 1
Affected Version To: 8.0.5
Patch Exists: NO
Related CWE:
CPE: a:wordpress:advanced_page_visit_counter:8.0.5
Platforms Tested: Kali-Linux, Windows 10, Windows 11
2023
Advanced Page Visit Counter 1.0 – Admin+ Stored Cross-Site Scripting (XSS) (Authenticated)
The Advanced Page Visit Counter plugin for WordPress version 8.0.5 is vulnerable to Stored Cross-Site Scripting (XSS) attacks. A high privilege user such as an admin can execute malicious scripts in the plugin's settings, even if the unfiltered_html capability is restricted.
Mitigation:
To mitigate this vulnerability, it is recommended to update the plugin to the latest version as soon as a patch is released. Additionally, users should avoid inputting untrusted data into the plugin's settings.