CVE-2026-97347 Overview
CVE-2026-97347 affects the Post Views Stats Counter plugin for WordPress in all versions up to and including 1.1.7. The plugin stores visitor User-Agent header values without proper sanitization or output escaping, enabling stored Cross-Site Scripting (XSS) [CWE-79]. Unauthenticated attackers can inject arbitrary JavaScript that executes when any user views an affected page. The plugin's only defense is a substring blacklist matching common bot signatures such as bot, spider, and crawler. Attackers bypass this filter by crafting a User-Agent string that omits those tokens.
Critical Impact
Unauthenticated attackers can inject persistent JavaScript payloads through the User-Agent header, executing scripts in the browser context of any visitor or administrator viewing pages that render the stored value.
Affected Products
- Post Views Stats Counter plugin for WordPress
- All versions up to and including 1.1.7
- WordPress sites with the plugin activated
Discovery Timeline
- 2026-09-30 - CVE-2026-97347 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-97347
Vulnerability Analysis
The Post Views Stats Counter plugin captures the HTTP User-Agent header from incoming visitors to log page-view statistics. The captured string is written to the database and later rendered in the WordPress admin interface and public output paths without HTML escaping. Because attackers control the User-Agent header, they can supply payloads containing <script> tags or event-handler attributes that execute in the browser of anyone viewing the stored data.
The attack requires no authentication and no user interaction beyond a victim loading a page that renders the stored value. Because the payload persists in the database, a single HTTP request can affect every subsequent viewer, including administrators accessing the plugin's dashboard views.
Root Cause
The root cause is insufficient input sanitization combined with missing output escaping in the plugin's view-tracking code paths. Relevant source locations include manage/admin.php (lines 447 and 681) and wp_pvscounter.php (lines 269 and 411), where the User-Agent value is handled without functions such as esc_html() or wp_kses(). The only filter applied is a substring match against known bot keywords, which serves an anti-spam purpose rather than a security purpose.
Attack Vector
An attacker sends an HTTP request to any tracked page with a crafted User-Agent header. The header value must avoid the blacklisted substrings (bot, spider, crawler) so the plugin records it. Once stored, the payload executes whenever the value is rendered in a page or the admin dashboard. Successful exploitation enables session hijacking, administrative action forgery, or redirection to attacker-controlled infrastructure.
For deeper technical detail, review the Wordfence Vulnerability Report and the plugin source at the WordPress Plugin Trac.
Detection Methods for CVE-2026-97347
Indicators of Compromise
- HTTP access logs containing User-Agent values with <script>, onerror=, onload=, or javascript: substrings
- Database rows in plugin-managed tables storing User-Agent fields that contain HTML tags or JavaScript event handlers
- Unexpected outbound requests from administrator browsers when accessing the plugin's dashboard pages
- Newly created WordPress administrator accounts or modified user roles following visits to the plugin's stats views
Detection Strategies
- Query WordPress database tables owned by the plugin for stored User-Agent values containing <, >, or = characters.
- Parse web-server access logs for anomalous User-Agent strings that include HTML or JavaScript syntax.
- Monitor administrative sessions for unexpected DOM modifications or script execution while viewing plugin dashboards.
Monitoring Recommendations
- Enable Web Application Firewall (WAF) rules that inspect and block User-Agent headers containing script tags or HTML event handlers.
- Alert on repeated requests from a single source that supply unusual User-Agent values not matching known browsers or crawlers.
- Audit WordPress user and role changes on a scheduled basis to detect privilege escalation resulting from stored XSS exploitation.
How to Mitigate CVE-2026-97347
Immediate Actions Required
- Deactivate the Post Views Stats Counter plugin until a patched version is available.
- Inspect the plugin's database tables and remove any rows containing script content in User-Agent fields.
- Rotate WordPress administrator credentials and invalidate active sessions if suspicious dashboard activity is observed.
- Review installed WordPress plugins and remove any that are unmaintained or unnecessary.
Patch Information
As of the CVE publication date (2026-09-30), no patched version beyond 1.1.7 is referenced in the available advisory data. Site owners should monitor the WordPress plugin directory and the Wordfence Vulnerability Report for release of a fixed version and apply it immediately upon availability.
Workarounds
- Deploy WAF rules that reject inbound requests where the User-Agent header contains HTML angle brackets or JavaScript keywords.
- Restrict access to /wp-admin/ pages by IP allowlist to reduce exposure of administrator browsers to stored payloads.
- Replace the plugin with a maintained analytics alternative that properly escapes stored client-supplied data.
# Example ModSecurity rule to block script content in User-Agent headers
SecRule REQUEST_HEADERS:User-Agent "@rx (?i)(<script|onerror=|onload=|javascript:)" \
"id:1009001,phase:1,deny,status:403,log,\
msg:'Blocked XSS payload in User-Agent header (CVE-2026-97347)'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
