Showing 1 vulnerability on this page for page_view_count

Signals CISA KEV Ransomware Nuclei
a3rev vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Page Views Count < 2.4.15 - Unauthenticated SQL Injection

The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks

CWE-89Mar 7, 20221 related artifact
CVSS9.8v3.1EPSS14.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX