CVE-2025-2164

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 15, 2025
Updated: Mar 28, 2025
CWE ID 476

Summary

CVE-2025-2164 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the pixelstats plugin for WordPress. The flaw, present in all versions up to 0.8.2, stems from insufficient input sanitization and output escaping on the 'post_id' and 'sortby' parameters. Maliciously crafted input can lead to the injection of arbitrary web scripts. Unauthenticated attackers can exploit this vulnerability by tricking a user into clicking on a specially crafted link, potentially leading to significant security risks such as data theft or unauthorized account access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share