plugin

Page Views Count Vulnerabilities

13 known security issues reported for the Page Views Count WordPress plugin. Most recent disclosed Dec 9, 2025.

1 critical 2 high 3 medium

Running Page Views Count on your site? Check whether your installed version is affected.

Scan your site free

Page View Count [page-views-count] <= 2.8.7 (unfixed)

unknown

[en] Missing Authorization vulnerability in Steve Truman Page View Count page-views-count allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Page View Count: from n/a through <= 2.8.7.

Affected:
up to 2.8.7
Fix:
No patched version reported
Disclosed:
Dec 9, 2025

CVE-2025-63034 on NVD →

Page View Count <= 2.9.1 - Missing Authorization to Authenticated (Subscriber+) Settings Update

medium

The Page View Count plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin settings.

CVSS:
4.3
Affected:
up to 2.9.1
Fixed in:
2.9.2
Disclosed:
Dec 8, 2025

CVE-2025-63034 on NVD →

Page View Count 2.8.0 - 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update

high

The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the yellow_message_dontshow() function in versions 2.8.0 to 2.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and ab...

CVSS:
8.1
Affected:
2.8.0 – 2.8.4
Fixed in:
2.8.5
Disclosed:
Apr 30, 2025

CVE-2025-2816 on NVD →

Page View Count [page-views-count] < 2.5.0

unknown

Update the WordPress Page View Count plugin to the latest available version (at least 2.5.0). An unknown person discovered and reported this Settings Change vulnerability in WordPress Page View Count Plugin. This vulnerability has been fixed in version 2.5.0.

Affected:
up to 2.5.0
Fixed in:
2.5.0
Disclosed:
Feb 22, 2023

Page View Count [page-views-count] < 2.6.1

unknown

[en] The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 2.6.1
Fixed in:
2.6.1
Disclosed:
Feb 6, 2023

CVE-2023-0095 on NVD →

Page View Count <= 2.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Page View Count plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and...

CVSS:
6.4
Affected:
up to 2.6.0
Fixed in:
2.6.1
Disclosed:
Jan 10, 2023

CVE-2023-0095 on NVD →

Page View Count [page-views-count] < 2.5.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Page View Count plugin <= 2.5.5 on WordPress allows an attacker to reset the plugin settings.

Affected:
up to 2.5.6
Fixed in:
2.5.6
Disclosed:
Nov 3, 2022

CVE-2022-40131 on NVD →

Page View Count <= 2.5.5 - Cross-Site Request Forgery

high

The Page View Count plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.5. This is due to missing or incorrect nonce validation on the reset_settings function. This makes it possible for unauthenticated attackers to reset the plugin's settings, via forged request grant...

CVSS:
8.8
Affected:
up to 2.5.5
Fixed in:
2.5.6
Disclosed:
Oct 13, 2022

CVE-2022-40131 on NVD →

Page View Count [page-views-count] < 2.4.15

unknown

[en] The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

Affected:
up to 2.4.15
Fixed in:
2.4.15
Disclosed:
Mar 7, 2022

CVE-2022-0434 on NVD →

Page Views Count Plugin <= 2.4.14 - Unauthenticated SQL Injection

critical

The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

CVSS:
9.8
Affected:
up to 2.4.15
Fixed in:
2.4.15
Disclosed:
Feb 1, 2022

CVE-2022-0434 on NVD →

Page View Count [page-views-count] < 2.4.9

unknown

[en] The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing users with a role as low as Contributor to perform Stored XSS attacks. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however,...

Affected:
up to 2.4.9
Fixed in:
2.4.9
Disclosed:
Aug 9, 2021

CVE-2021-24509 on NVD →

Page View Counts <= 2.4.8 - Contributor+ Stored Cross-Site Scripting

medium

The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing users with a role as low as Contributor to perform Stored XSS attacks. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, high...

CVSS:
5.4
Affected:
up to 2.4.8
Fixed in:
2.4.9
Disclosed:
Jul 12, 2021

CVE-2021-24509 on NVD →

Page View Count [page-views-count] >= 2.8.0 - <= 2.8.4

unknown
Affected:
2.8.0 – 2.8.4
Fixed in:
2.8.4

CVE-2025-2816 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database