Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-61431
HistoryAug 11, 2021 - 12:00 a.m.

WordPress Cross-Site Scripting Vulnerability (CNVD-2021-61431)

2021-08-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
wordpress
xss
page view count

EPSS

0.001

Percentile

24.8%

WordPress is the WordPress (Wordpress) Foundation’s set of blogging platforms developed using the PHP language. A cross-site scripting vulnerability exists in the Page View Count plugin for WordPress prior to 2.4.9, which fails to escape the postid parameter of the pvc_stats shortcode, allowing users down to the Contributor role to perform stored XSS attack. No details of the vulnerability are currently available.

EPSS

0.001

Percentile

24.8%