Kento Post View Counter [kento-post-view-counter] <= 2.8 (unfixed + closed)
unknown
[en] The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in versions up to, and including, 2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticat...
- Affected:
- up to 2.8
- Fix:
- No patched version reported
- Disclosed:
- Oct 16, 2024
CVE-2016-15040 on NVD →
Kento Post View Counter [kento-post-view-counter] <= 2.8
unknown
[en] The kento-post-view-counter plugin through 2.8 for WordPress has stored XSS via kento_pvc_numbers_lang, kento_pvc_today_text, or kento_pvc_total_text.
- Affected:
- up to 2.8
- Fixed in:
- 2.8
- Disclosed:
- Sep 17, 2019
CVE-2016-10981 on NVD →
Kento Post View Counter [kento-post-view-counter] <= 2.8
unknown
[en] The kento-post-view-counter plugin through 2.8 for WordPress has XSS via kento_pvc_geo.
- Affected:
- up to 2.8
- Fixed in:
- 2.8
- Disclosed:
- Sep 17, 2019
CVE-2016-10980 on NVD →
Kento Post View Counter [kento-post-view-counter] <= 2.8
unknown
[en] The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.
- Affected:
- up to 2.8
- Fixed in:
- 2.8
- Disclosed:
- Sep 17, 2019
CVE-2016-10982 on NVD →
Kento Post View Counter <= 2.8 - SQL Injection
critical
The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in versions up to, and including, 2.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated at...
- CVSS:
- 9.8
- Affected:
- up to 2.8
- Fix:
- No patched version reported
- Disclosed:
- May 26, 2016
CVE-2016-15040 on NVD →
Kento Post View Counter [kento-post-view-counter] < 2.9 (closed)
unknown
Kento Post View Counter plugin is prone to multiple CSRF and XSS vulnerabilities. It allows an attacker to attack almost all the pages of the website and execute malicious JavaScript payload on all clients that are visiting that website.
Upgrade the plugin.
- Affected:
- up to 2.9
- Fixed in:
- 2.9
- Disclosed:
- Apr 18, 2016
Kento Post View Counter <= 2.8 - Cross-Site Request Forgery
high
The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.
- CVSS:
- 8.8
- Affected:
- up to 2.8
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2016
CVE-2016-10982 on NVD →
Kento Post View Counter <= 2.8 - Stored Cross-Site Scripting
medium
The kento-post-view-counter plugin through 2.8 for WordPress has stored XSS via kento_pvc_numbers_lang, kento_pvc_today_text, or kento_pvc_total_text.
- CVSS:
- 6.1
- Affected:
- up to 2.8
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2016
CVE-2016-10981 on NVD →
Kento Post View Counter <= 2.8 - Reflected Cross-Site Scripting
medium
The kento-post-view-counter plugin through 2.8 for WordPress has XSS via kento_pvc_geo.
- CVSS:
- 6.1
- Affected:
- up to 2.8
- Fix:
- No patched version reported
- Disclosed:
- Apr 16, 2016
CVE-2016-10980 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database