Stored Cross-Site Scripting Vulnerability in Advanced Page Visit Counter Plugin for WordPress
CVE-2023-5529
What is CVE-2023-5529?
The Advanced Page Visit Counter plugin for WordPress, prior to version 8.0.6, contains a vulnerability that fails to properly sanitize and escape certain settings. This security flaw can lead to Stored Cross-Site Scripting (XSS) attacks, allowing users with high privileges, such as administrators, to execute harmful scripts on affected sites. Even in scenarios where the unfiltered_html capability is restricted, such as in a multisite environment, the vulnerability remains exploitable, potentially compromising site integrity and user data.
Affected Version(s)
Advanced Page Visit Counter 0 < 8.0.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved