VulnerabilityModified
CVE-2021-25086
The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it
MEDIUM 6.1EPSS 1.30%
Does this matter?
Lower severity and a low EPSS score (1.30%). Track it; it rarely justifies an emergency change on its own.
Description
The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting it in an admin dashboard page, allowing unauthenticated attackers to perform Cross-Site Scripting attacks against admins viewing it
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.30% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- advanced page visit counter project/advanced page visit counter
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/2cf9e517-d882-4af2-bd12-e700b75e7a11Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/2cf9e517-d882-4af2-bd12-e700b75e7a11Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.