First published: Sat Mar 15 2025(Updated: )
The pixelstats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' and 'sortby' parameters in all versions up to, and including, 0.8.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | <=0.8.2 | |
Pixelstats | <=0.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2164 is considered a medium severity vulnerability due to its potential for exploitation via reflected cross-site scripting.
To fix CVE-2025-2164, update the pixelstats plugin to version 0.8.3 or higher where the vulnerability has been addressed.
CVE-2025-2164 affects the pixelstats plugin for WordPress in all versions up to and including 0.8.2.
CVE-2025-2164 is a Reflected Cross-Site Scripting (XSS) vulnerability.
CVE-2025-2164 can be exploited by unauthenticated attackers through specific parameters in the plugin.