{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/post-views-stats-counter--1.1.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:post_views_stats_counter:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-97347"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Post Views Stats Counter (\u003c= 1.1.7)"],"_cs_severities":["high"],"_cs_tags":["web-application","xss","wordpress","cve-2026-97347"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eCVE-2026-97347 is a high-severity stored cross-site scripting (XSS) vulnerability affecting the WordPress plugin 'Post Views Stats Counter' versions 1.1.7 and below. The vulnerability stems from the plugin's failure to sanitize the \u003ccode\u003eUser-Agent\u003c/code\u003e HTTP header before storing it in the database and subsequently rendering it raw on the administrator's stats dashboard (\u003ccode\u003eoptions-general.php?page=post_views_stats_admin_menu\u003c/code\u003e).\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can craft a malicious HTTP request containing a JavaScript payload within the \u003ccode\u003eUser-Agent\u003c/code\u003e header. Since the plugin's only defense is a weak, substring-based blacklist for \u0026quot;bot\u0026quot;, \u0026quot;spider\u0026quot;, and \u0026quot;crawler\u0026quot;, these requests are stored in the \u003ccode\u003ewp_pvs_counter\u003c/code\u003e table. When an administrator accesses the plugin's stats page, the injected script executes in their browser session. This allows for session hijacking, unauthorized administrative actions, or the installation of malicious plugins to achieve remote code execution (RCE). The payload is restricted to 155 characters due to database column constraints.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running the vulnerable 'Post Views Stats Counter' plugin.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET request targeting any public URL on the target site.\u003c/li\u003e\n\u003cli\u003eAttacker sets the \u003ccode\u003eUser-Agent\u003c/code\u003e header to include a JavaScript payload, ensuring the string does not contain 'bot', 'spider', or 'crawler'.\u003c/li\u003e\n\u003cli\u003eThe plugin's \u003ccode\u003ewp_pvscounter.php\u003c/code\u003e script checks the header against the weak bot blacklist.\u003c/li\u003e\n\u003cli\u003eThe server records the unsanitized \u003ccode\u003eUser-Agent\u003c/code\u003e string directly into the \u003ccode\u003ewp_pvs_counter\u003c/code\u003e database table.\u003c/li\u003e\n\u003cli\u003eAn administrator logs into the WordPress dashboard and navigates to the 'Post Views Stats Counter' settings page.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003emanage/admin.php\u003c/code\u003e file renders the stored \u003ccode\u003eUser-Agent\u003c/code\u003e content within the administrative dashboard without sanitization.\u003c/li\u003e\n\u003cli\u003eThe injected JavaScript executes within the administrator's browser session, facilitating session hijacking or further compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full compromise of the administrator's session. Potential impacts include the theft of session cookies, the ability to perform unauthorized administrative actions, and the modification of site settings. Furthermore, attackers can install and activate arbitrary plugins, leading to full remote code execution on the server. The payload is persistent, meaning it will trigger every time the administrator views the statistics page until the database entry is manually deleted.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately disable or uninstall the 'Post Views Stats Counter' plugin until a patched version is confirmed available and deployed.\u003c/li\u003e\n\u003cli\u003eImplement an aggressive Web Application Firewall (WAF) rule to block incoming HTTP requests with suspicious \u003ccode\u003eUser-Agent\u003c/code\u003e headers containing script tags (\u003ccode\u003e\u0026lt;script\u0026gt;\u003c/code\u003e, \u003ccode\u003eonerror\u003c/code\u003e, \u003ccode\u003eonload\u003c/code\u003e, etc.) targeting the WordPress application.\u003c/li\u003e\n\u003cli\u003eConduct a security audit of administrative logs to identify unauthorized plugin installations or configuration changes.\u003c/li\u003e\n\u003cli\u003eIf signs of compromise are detected, force a reset of all administrator passwords and invalidate existing session cookies.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-30T12:18:20Z","date_published":"2026-09-30T12:18:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97347-xss/","summary":"An unauthenticated stored XSS vulnerability in the Post Views Stats Counter WordPress plugin (\u003c= 1.1.7) allows attackers to inject malicious JavaScript into the administrator's dashboard via the User-Agent header.","title":"Stored XSS in Post Views Stats Counter WordPress Plugin (CVE-2026-97347)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-97347-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Post Views Stats Counter (\u003c= 1.1.7)","version":"https://jsonfeed.org/version/1.1"}