Impact
The WordPress WP Views Counter plugin up to version 2.1.2 contains a missing authorization flaw that permits users with insufficient privileges to bypass intended access restrictions. This broken access control is a CWE-862 weakness, allowing an attacker to read or manipulate data that should be protected by the plugin’s security settings. The potential consequence is unauthorized access to statistical information or other protected data within the WordPress site, possibly revealing usage metrics or facilitating further exploitation if combined with other vulnerabilities.
Affected Systems
The affected product is etruel WP Views Counter (wpecounter). All releases from an unspecified initial version up through 2.1.2 are impacted.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability is considered moderate severity. The EPSS score indicates a very low but non‑zero likelihood of exploitation. It is not currently listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be web‑based, requiring access to the WP Views Counter interface or an authenticated user’s session with misapplied capability checks. No special conditions are stated in the data, so the flaw is likely exploitable by users who can reach the plugin’s endpoints.
OpenCVE Enrichment