Cross-site Scripting Vulnerability in Kama Click Counter by Timur Kamaev
CVE-2025-49861

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2025

What is CVE-2025-49861?

The Kama Click Counter plugin, developed by Timur Kamaev, suffers from a Cross-site Scripting (XSS) vulnerability, allowing attackers to inject malicious scripts that are stored and executed on users' browsers. This could mean a serious threat to website integrity and user data security, especially in versions up to 4.0.3. Protect your site by ensuring you have the latest security patches and practicing safe coding standards.

Affected Version(s)

Kama Click Counter <= 4.0.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

muhammad yudha (Patchstack Alliance)
.