CPE
An unauthenticated stored XSS vulnerability in the Post Views Stats Counter WordPress plugin (<= 1.1.7) allows attackers to inject malicious JavaScript into the administrator's dashboard via the User-Agent header.