Page View Count [page-views-count] <= 2.8.7 (unfixed)
unknown
[en] Missing Authorization vulnerability in Steve Truman Page View Count page-views-count allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Page View Count: from n/a through <= 2.8.7.
- Affected:
- up to 2.8.7
- Fix:
- No patched version reported
- Disclosed:
- Dec 9, 2025
CVE-2025-63034 on NVD →
Page View Count <= 2.9.1 - Missing Authorization to Authenticated (Subscriber+) Settings Update
medium
The Page View Count plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.9.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update plugin settings.
- CVSS:
- 4.3
- Affected:
- up to 2.9.1
- Fixed in:
- 2.9.2
- Disclosed:
- Dec 8, 2025
CVE-2025-63034 on NVD →
Page View Count 2.8.0 - 2.8.4 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
high
The Page View Count plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the yellow_message_dontshow() function in versions 2.8.0 to 2.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and ab...
- CVSS:
- 8.1
- Affected:
- 2.8.0 – 2.8.4
- Fixed in:
- 2.8.5
- Disclosed:
- Apr 30, 2025
CVE-2025-2816 on NVD →
Page View Count [page-views-count] < 2.5.0
unknown
Update the WordPress Page View Count plugin to the latest available version (at least 2.5.0).
An unknown person discovered and reported this Settings Change vulnerability in WordPress Page View Count Plugin. This vulnerability has been fixed in version 2.5.0.
- Affected:
- up to 2.5.0
- Fixed in:
- 2.5.0
- Disclosed:
- Feb 22, 2023
Page View Count [page-views-count] < 2.6.1
unknown
[en] The Page View Count WordPress plugin before 2.6.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
- Affected:
- up to 2.6.1
- Fixed in:
- 2.6.1
- Disclosed:
- Feb 6, 2023
CVE-2023-0095 on NVD →
Page View Count <= 2.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Page View Count plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 2.6.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor level and...
- CVSS:
- 6.4
- Affected:
- up to 2.6.0
- Fixed in:
- 2.6.1
- Disclosed:
- Jan 10, 2023
CVE-2023-0095 on NVD →
Page View Count [page-views-count] < 2.5.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in a3rev Software Page View Count plugin <= 2.5.5 on WordPress allows an attacker to reset the plugin settings.
- Affected:
- up to 2.5.6
- Fixed in:
- 2.5.6
- Disclosed:
- Nov 3, 2022
CVE-2022-40131 on NVD →
Page View Count <= 2.5.5 - Cross-Site Request Forgery
high
The Page View Count plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.5.5. This is due to missing or incorrect nonce validation on the reset_settings function. This makes it possible for unauthenticated attackers to reset the plugin's settings, via forged request grant...
- CVSS:
- 8.8
- Affected:
- up to 2.5.5
- Fixed in:
- 2.5.6
- Disclosed:
- Oct 13, 2022
CVE-2022-40131 on NVD →
Page View Count [page-views-count] < 2.4.15
unknown
[en] The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks
- Affected:
- up to 2.4.15
- Fixed in:
- 2.4.15
- Disclosed:
- Mar 7, 2022
CVE-2022-0434 on NVD →
Page Views Count Plugin <= 2.4.14 - Unauthenticated SQL Injection
critical
The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks
- CVSS:
- 9.8
- Affected:
- up to 2.4.15
- Fixed in:
- 2.4.15
- Disclosed:
- Feb 1, 2022
CVE-2022-0434 on NVD →
Page View Count [page-views-count] < 2.4.9
unknown
[en] The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing users with a role as low as Contributor to perform Stored XSS attacks. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however,...
- Affected:
- up to 2.4.9
- Fixed in:
- 2.4.9
- Disclosed:
- Aug 9, 2021
CVE-2021-24509 on NVD →
Page View Counts <= 2.4.8 - Contributor+ Stored Cross-Site Scripting
medium
The Page View Count WordPress plugin before 2.4.9 does not escape the postid parameter of pvc_stats shortcode, allowing users with a role as low as Contributor to perform Stored XSS attacks. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, high...
- CVSS:
- 5.4
- Affected:
- up to 2.4.8
- Fixed in:
- 2.4.9
- Disclosed:
- Jul 12, 2021
CVE-2021-24509 on NVD →
Page View Count [page-views-count] >= 2.8.0 - <= 2.8.4
unknown
- Affected:
- 2.8.0 – 2.8.4
- Fixed in:
- 2.8.4
CVE-2025-2816 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database