Post Views Counter [post-views-counter] < 1.4.5
unknown[en] Unauthenticated Cross Site Request Forgery (CSRF) in Post Views Counter <= 1.4.4 versions.
- Affected:
- up to 1.4.5
- Fixed in:
- 1.4.5
- Disclosed:
- Apr 12, 2024
plugin
4 known security issues reported for the Post Views Counter WordPress plugin. Most recent disclosed Apr 12, 2024.
Running Post Views Counter on your site? Check whether your installed version is affected.
Scan your site free[en] Unauthenticated Cross Site Request Forgery (CSRF) in Post Views Counter <= 1.4.4 versions.
The Post Views Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation on the save_bulk_post_views() function. This makes it possible for unauthenticated attackers to save bulk post views via a forged request...
[en] The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed
The Post Views Counter WordPress plugin before 1.3.5 does not sanitise or escape its Post Views Label settings, which could allow high privilege users to perform Cross-Site Scripting attacks in the frontend even when the unfiltered_html capability is disallowed
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free