CVE-2025-12452 - CVE House
Back to Database
Status published Medium CVE-2025-12452

Visit Counter 1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Vulnerability Description

The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing or incorrect nonce validation on the widgets.php page. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12452

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Mohammadamin Alidoost

Affected Vendor

bestiadurmiente

View all reports →

Affected Software

Visit Counter
Vulnerable Versions:
1.0

Timeline

Official Publish: November 4th, 2025
Last Modified: November 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)