<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:wordpress:post_views_stats_counter:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awordpresspost_views_stats_counter/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 12:18:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awordpresspost_views_stats_counter/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Post Views Stats Counter WordPress Plugin (CVE-2026-97347)</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97347-xss/</link><pubDate>Wed, 30 Sep 2026 12:18:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97347-xss/</guid><description>An unauthenticated stored XSS vulnerability in the Post Views Stats Counter WordPress plugin (&lt;= 1.1.7) allows attackers to inject malicious JavaScript into the administrator's dashboard via the User-Agent header.</description><content:encoded><![CDATA[<p>CVE-2026-97347 is a high-severity stored cross-site scripting (XSS) vulnerability affecting the WordPress plugin 'Post Views Stats Counter' versions 1.1.7 and below. The vulnerability stems from the plugin's failure to sanitize the <code>User-Agent</code> HTTP header before storing it in the database and subsequently rendering it raw on the administrator's stats dashboard (<code>options-general.php?page=post_views_stats_admin_menu</code>).</p>
<p>An unauthenticated attacker can craft a malicious HTTP request containing a JavaScript payload within the <code>User-Agent</code> header. Since the plugin's only defense is a weak, substring-based blacklist for &quot;bot&quot;, &quot;spider&quot;, and &quot;crawler&quot;, these requests are stored in the <code>wp_pvs_counter</code> table. When an administrator accesses the plugin's stats page, the injected script executes in their browser session. This allows for session hijacking, unauthorized administrative actions, or the installation of malicious plugins to achieve remote code execution (RCE). The payload is restricted to 155 characters due to database column constraints.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a WordPress site running the vulnerable 'Post Views Stats Counter' plugin.</li>
<li>Attacker crafts a malicious HTTP GET request targeting any public URL on the target site.</li>
<li>Attacker sets the <code>User-Agent</code> header to include a JavaScript payload, ensuring the string does not contain 'bot', 'spider', or 'crawler'.</li>
<li>The plugin's <code>wp_pvscounter.php</code> script checks the header against the weak bot blacklist.</li>
<li>The server records the unsanitized <code>User-Agent</code> string directly into the <code>wp_pvs_counter</code> database table.</li>
<li>An administrator logs into the WordPress dashboard and navigates to the 'Post Views Stats Counter' settings page.</li>
<li>The <code>manage/admin.php</code> file renders the stored <code>User-Agent</code> content within the administrative dashboard without sanitization.</li>
<li>The injected JavaScript executes within the administrator's browser session, facilitating session hijacking or further compromise.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full compromise of the administrator's session. Potential impacts include the theft of session cookies, the ability to perform unauthorized administrative actions, and the modification of site settings. Furthermore, attackers can install and activate arbitrary plugins, leading to full remote code execution on the server. The payload is persistent, meaning it will trigger every time the administrator views the statistics page until the database entry is manually deleted.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately disable or uninstall the 'Post Views Stats Counter' plugin until a patched version is confirmed available and deployed.</li>
<li>Implement an aggressive Web Application Firewall (WAF) rule to block incoming HTTP requests with suspicious <code>User-Agent</code> headers containing script tags (<code>&lt;script&gt;</code>, <code>onerror</code>, <code>onload</code>, etc.) targeting the WordPress application.</li>
<li>Conduct a security audit of administrative logs to identify unauthorized plugin installations or configuration changes.</li>
<li>If signs of compromise are detected, force a reset of all administrator passwords and invalidate existing session cookies.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>xss</category><category>wordpress</category><category>cve-2026-97347</category></item></channel></rss>