Sceawere

Vulnerability Detail

CVE-2026-97347UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Stored XSS via User-Agent

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
kazukiyanamoto
Product
Post Views Stats Counter
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Post Views Stats Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The plugin's only input filter is a substring blacklist for known bot signatures (e.g. 'bot', 'spider', 'crawler'), which can be trivially bypassed by crafting a User-Agent payload that omits those strings.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-30T09:17:16.773Z",
  "pubdate": "2026-09-30T09:17:16.773Z",
  "executiveSummary": "The Post Views Stats Counter plugin for WordPress, in all versions up to and including 1.1.7, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This flaw originates from the improper handling of User-Agent HTTP headers, which are processed and stored by the plugin without adequate sanitization or output encoding. Unauthenticated remote attackers can exploit this vulnerability by submitting specially crafted HTTP requests containing malicious JavaScript payloads within the User-Agent header field. When an administrator or privileged user views the statistics dashboard populated by the plugin, the malicious script executes within the context of their session. This compromise can lead to unauthorized actions, session hijacking, credential theft, or further administrative compromise of the WordPress installation. Because the attack requires no authentication and targets the administrative interface, the risk profile is categorized as critical. The current security control relies on a flawed blocklist approach that fails to prevent malicious inputs, necessitating immediate remediation efforts to protect the integrity of the administrative dashboard.",
  "technicalDetails": "The vulnerability resides in the way Post Views Stats Counter processes the 'HTTP_USER_AGENT' server variable before logging or displaying the data in the WordPress administrative interface. The core logic lacks robust input validation and fails to implement contextual output escaping, allowing raw, user-supplied data to be reflected directly into the Document Object Model (DOM) of the statistics dashboard.\nThe root cause is a reliance on an ineffective security control: a hardcoded substring blacklist designed to filter out known bot signatures, such as 'bot', 'spider', or 'crawler'. This implementation is cryptographically and logically deficient, as it provides no protection against arbitrary payloads that do not contain these specific substrings. Attackers can trivially bypass this filter by crafting a malicious User-Agent string that embeds executable JavaScript tags (e.g., <script>alert(document.cookie)</script>) while omitting the blacklisted keywords.\nThe attack flow follows a predictable sequence: First, an unauthenticated attacker identifies that the plugin tracks site visits by recording the User-Agent string of incoming HTTP requests. Second, the attacker transmits an HTTP request to the WordPress site, manually setting the User-Agent header to contain an XSS payload. Third, the plugin captures this header and stores it in the database associated with site visit statistics. Fourth, the malicious payload remains dormant in the database until an administrator navigates to the plugin’s statistics page within the WordPress dashboard.\nWhen the administrative page renders the stored visit data, the browser interprets the injected payload as legitimate script content, executing the attacker's code. This execution occurs within the security context of the logged-in administrator. The impact is significant, as the malicious script can perform any action the administrator is authorized to execute, such as creating new administrative accounts, modifying plugin settings, injecting additional persistent backdoors, or exfiltrating session tokens via cross-site request forgery (CSRF) or document cookie access. Because the plugin does not escape the data during output rendering, the application fails to mitigate the persistence of the stored XSS. The vulnerability affects all versions up to 1.1.7 and is remotely exploitable without prerequisites, significantly expanding the attack surface for site administrators."
}
CVE-2026-97347: Stored XSS via User-Agent (HIGH Severity, CVSS: 7.2) | Sceawere