Impact
The WP Views Counter plugin contains a stored cross‑site scripting flaw that arises when user‑supplied data is not properly escaped before rendering. Once injected, malicious JavaScript runs in the context of any user who views a page displaying the counter, potentially enabling defacement, cookie theft or session hijacking.
Affected Systems
WordPress sites that run the etruel WP Views Counter plugin version 2.0.3 or earlier are affected. All installations from the first release up to and including 2.0.3 are vulnerable regardless of WordPress version.
Risk and Exploitability
The CVSS score of 6.5 signals a moderate severity. The EPSS score is less than 1%, indicating that exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalogue. Exploitation requires injection of a payload into a field processed and stored by the plugin, which will then execute when the counter is displayed to other users. The attack vector is likely remote and depends on the site’s exposure of the vulnerable input surface.
OpenCVE Enrichment
EUVD