Skip to content
Threat Feed
high advisory

Stored XSS in Post Views Stats Counter WordPress Plugin (CVE-2026-97347)

An unauthenticated stored XSS vulnerability in the Post Views Stats Counter WordPress plugin (<= 1.1.7) allows attackers to inject malicious JavaScript into the administrator's dashboard via the User-Agent header.

CVE search metadata

CVE search record: CVE-2026-97347. Severity: high. CVSS: 7.2. KEV: no. Product: Post Views Stats Counter (<= 1.1.7). Brief: Stored XSS in Post Views Stats Counter WordPress Plugin (CVE-2026-97347). Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97347-xss/

CVE-2026-97347 is a high-severity stored cross-site scripting (XSS) vulnerability affecting the WordPress plugin 'Post Views Stats Counter' versions 1.1.7 and below. The vulnerability stems from the plugin's failure to sanitize the User-Agent HTTP header before storing it in the database and subsequently rendering it raw on the administrator's stats dashboard (options-general.php?page=post_views_stats_admin_menu).

An unauthenticated attacker can craft a malicious HTTP request containing a JavaScript payload within the User-Agent header. Since the plugin's only defense is a weak, substring-based blacklist for "bot", "spider", and "crawler", these requests are stored in the wp_pvs_counter table. When an administrator accesses the plugin's stats page, the injected script executes in their browser session. This allows for session hijacking, unauthorized administrative actions, or the installation of malicious plugins to achieve remote code execution (RCE). The payload is restricted to 155 characters due to database column constraints.

Attack Chain

  1. Attacker identifies a WordPress site running the vulnerable 'Post Views Stats Counter' plugin.
  2. Attacker crafts a malicious HTTP GET request targeting any public URL on the target site.
  3. Attacker sets the User-Agent header to include a JavaScript payload, ensuring the string does not contain 'bot', 'spider', or 'crawler'.
  4. The plugin's wp_pvscounter.php script checks the header against the weak bot blacklist.
  5. The server records the unsanitized User-Agent string directly into the wp_pvs_counter database table.
  6. An administrator logs into the WordPress dashboard and navigates to the 'Post Views Stats Counter' settings page.
  7. The manage/admin.php file renders the stored User-Agent content within the administrative dashboard without sanitization.
  8. The injected JavaScript executes within the administrator's browser session, facilitating session hijacking or further compromise.

Impact

Successful exploitation results in full compromise of the administrator's session. Potential impacts include the theft of session cookies, the ability to perform unauthorized administrative actions, and the modification of site settings. Furthermore, attackers can install and activate arbitrary plugins, leading to full remote code execution on the server. The payload is persistent, meaning it will trigger every time the administrator views the statistics page until the database entry is manually deleted.

Recommendation

  1. Immediately disable or uninstall the 'Post Views Stats Counter' plugin until a patched version is confirmed available and deployed.
  2. Implement an aggressive Web Application Firewall (WAF) rule to block incoming HTTP requests with suspicious User-Agent headers containing script tags (<script>, onerror, onload, etc.) targeting the WordPress application.
  3. Conduct a security audit of administrative logs to identify unauthorized plugin installations or configuration changes.
  4. If signs of compromise are detected, force a reset of all administrator passwords and invalidate existing session cookies.

Immediate actions

Disable Post Views Stats Counter plugin

IT Operations 24h

Mitigations

Disable the plugin and monitor for malicious User-Agent patterns

immediate IT Operations

CVE-2026-97347

Detection coverage 1

Detect CVE-2026-97347 Exploitation - Malicious User-Agent Injection

high

Detects HTTP requests containing common XSS vectors in the User-Agent header, which may be attempting to exploit the Post Views Stats Counter vulnerability.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →