CVE-2025-2164
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2025-2164 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the pixelstats plugin for WordPress. The flaw, present in all versions up to 0.8.2, stems from insufficient input sanitization and output escaping on the 'post_id' and 'sortby' parameters. Maliciously crafted input can lead to the injection of arbitrary web scripts. Unauthenticated attackers can exploit this vulnerability by tricking a user into clicking on a specially crafted link, potentially leading to significant security risks such as data theft or unauthorized account access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.