plugin

Kento Post View Counter Vulnerabilities

9 known security issues reported for the Kento Post View Counter WordPress plugin. Most recent disclosed Oct 16, 2024.

1 critical 1 high 2 medium

Running Kento Post View Counter on your site? Check whether your installed version is affected.

Scan your site free

Kento Post View Counter [kento-post-view-counter] <= 2.8 (unfixed + closed)

unknown

[en] The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in versions up to, and including, 2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticat...

Affected:
up to 2.8
Fix:
No patched version reported
Disclosed:
Oct 16, 2024

CVE-2016-15040 on NVD →

Kento Post View Counter [kento-post-view-counter] <= 2.8

unknown

[en] The kento-post-view-counter plugin through 2.8 for WordPress has stored XSS via kento_pvc_numbers_lang, kento_pvc_today_text, or kento_pvc_total_text.

Affected:
up to 2.8
Fixed in:
2.8
Disclosed:
Sep 17, 2019

CVE-2016-10981 on NVD →

Kento Post View Counter [kento-post-view-counter] <= 2.8

unknown

[en] The kento-post-view-counter plugin through 2.8 for WordPress has XSS via kento_pvc_geo.

Affected:
up to 2.8
Fixed in:
2.8
Disclosed:
Sep 17, 2019

CVE-2016-10980 on NVD →

Kento Post View Counter [kento-post-view-counter] <= 2.8

unknown

[en] The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.

Affected:
up to 2.8
Fixed in:
2.8
Disclosed:
Sep 17, 2019

CVE-2016-10982 on NVD →

Kento Post View Counter <= 2.8 - SQL Injection

critical

The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in versions up to, and including, 2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at...

CVSS:
9.8
Affected:
up to 2.8
Fix:
No patched version reported
Disclosed:
May 26, 2016

CVE-2016-15040 on NVD →

Kento Post View Counter [kento-post-view-counter] < 2.9 (closed)

unknown

Kento Post View Counter plugin is prone to multiple CSRF and XSS vulnerabilities. It allows an attacker to attack almost all the pages of the website and execute malicious JavaScript payload on all clients that are visiting that website. Upgrade the plugin.

Affected:
up to 2.9
Fixed in:
2.9
Disclosed:
Apr 18, 2016

Kento Post View Counter <= 2.8 - Cross-Site Request Forgery

high

The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.

CVSS:
8.8
Affected:
up to 2.8
Fix:
No patched version reported
Disclosed:
Apr 17, 2016

CVE-2016-10982 on NVD →

Kento Post View Counter <= 2.8 - Stored Cross-Site Scripting

medium

The kento-post-view-counter plugin through 2.8 for WordPress has stored XSS via kento_pvc_numbers_lang, kento_pvc_today_text, or kento_pvc_total_text.

CVSS:
6.1
Affected:
up to 2.8
Fix:
No patched version reported
Disclosed:
Apr 17, 2016

CVE-2016-10981 on NVD →

Kento Post View Counter <= 2.8 - Reflected Cross-Site Scripting

medium

The kento-post-view-counter plugin through 2.8 for WordPress has XSS via kento_pvc_geo.

CVSS:
6.1
Affected:
up to 2.8
Fix:
No patched version reported
Disclosed:
Apr 16, 2016

CVE-2016-10980 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database