QID 730497

Date Published: 2022-05-24

QID 730497: WordPress Plugin Page View Count SQL Injection Vulnerability

WordPress Page View Count plugin is simple to set up plugin that gives site visitors and site owners the ability to quickly and easily see how many people have visited that page or post.

CVE-2022-0434: The Page View Count WordPress plugin before 2.4.15 does not sanitise and escape the post_ids parameter before using it in a SQL statement via a REST endpoint, available to both unauthenticated and authenticated users. As a result, unauthenticated attackers could perform SQL injection attacks.

Affected Version:
Page View Count plugin versions prior to 2.4.15

QID Detection Logic(Unauthenticated): This unauthenticated detection will send a malicious query to post_ids parameter and tries to fetch the email from the system or detection also depends on the BlindElephant engine to detect the vulnerable version of the Page View Count plugin.

Successful exploitation of this vulnerability may allow an unauthenticated attacker to execute arbitrary SQL queries on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are requested to update to Page View Count Plugin 2.4.15 or later to mitigate this vulnerability.

    Vendor References

    CVEs related to QID 730497

    Software Advisories
    Advisory ID Software Component Link
    Page View Count Release Notes URL Logo wordpress.org/plugins/page-views-count/#developers