Impact
The vulnerability lies in the way the Post Views Stats Counter plugin records the HTTP User‑Agent header. It does not properly sanitize or escape the value before storing it in the database. Because the value is later printed on a page that is visited by any user, an attacker can embed arbitrary JavaScript. When a victim loads that page, the injected script runs in the victim’s browser with the privileges of the site, enabling cookie theft, session hijacking, defacement or other malicious actions. The weakness is a classic input validation flaw (CWE‑79).
Affected Systems
The only affected software is the Post Views Stats Counter WordPress plugin for the vendor kazukiyanamoto. All releases up to and including version 1.1.7 are vulnerable. No other vendors or products are listed.
Risk and Exploitability
The CVSS score is 7.2, indicating a high severity. The EPSS score is not available, but the vulnerability can be triggered by any unauthenticated user simply by sending a crafted User‑Agent header. The VSA is not in the CISA KEV catalog, yet the attack path is trivial and no authentication is required, so the risk to sites that deploy the plugin is moderate to high. Exfiltration or defacement costs are likely, especially if site visitors include privileged users.
OpenCVE Enrichment