What the vulnerability does
01Description
Missing Authorization vulnerability in Hugh Lashbrooke Post Hit Counter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Hit Counter: from n/a through 1.3.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Hugh Lashbrooke Post Hit Counter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Hit Counter: from n/a through 1.3.2.
Explanation of Vulnerability in Simple Terms
Post Hit Counter through version 1.3.2 lacks proper authorization checks, allowing authenticated users with low privileges to modify counter data they should not access. The vulnerability requires a valid user account but no special permissions. Site administrators should update to a version newer than 1.3.2 to prevent unauthorized data manipulation.
What an attacker can do
Modify hit counter data for posts or pages they do not own or have permission to edit.
Potential impact on your site
Inaccurate or manipulated post view counts; potential data integrity issues if counters are used for analytics or reporting.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities