a3rev Vulnerabilities and Affected Products
Vulnerabilities associated with page_view_count.
Products
Clear product- a3 Lazy Load2 vulnerabilities
- Compare Products for WooCommerce2 vulnerabilities
- Contact Us Page – Contact People1 vulnerability
- Page View Count1 vulnerability
- page_view_count1 vulnerability
- Product Sort and Display for WooCommerce1 vulnerability
- WP Email Template1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-0434CRITICAL | Page Views Count < 2.4.15 - Unauthenticated SQL InjectionThe Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks | CVSS9.8v3.1 | EPSS14.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |