What the vulnerability does
01Description
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Mahlamusa Who Hit The Page – Hit Counter plugin <= 1.4.14.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Mahlamusa Who Hit The Page – Hit Counter plugin <= 1.4.14.3 versions.
Explanation of Vulnerability in Simple Terms
Who Hit The Page – Hit Counter versions up to 1.4.14.3 contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in visitors' browsers when they view the page. The vulnerability requires user interaction and network access but does not require authentication. Affected sites should update to a version newer than 1.4.14.3.
What an attacker can do
Inject malicious scripts that run in visitors' browsers and steal session data or redirect users.
Potential impact on your site
Visitors' browsers execute attacker-controlled scripts, risking credential theft and malware distribution.
Conditions required to exploit
Attacker needs network access; victim must visit the affected page (user interaction required).
Key dates
External resources
Related vulnerabilities