1 results (0.010 seconds)

CVSS: 6.8EPSS: 0%CPEs: 1EXPL: 1

25 Jan 2023 — The Post Views Count WordPress plugin through 3.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks The Post Views Count plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping on... • https://wpscan.com/vulnerability/ad163020-8b9c-42cb-a55f-b137b224bafb • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •