VYPR
Medium severity5.4NVD Advisory· Published Dec 9, 2025· Updated Apr 27, 2026

CVE-2025-63034

CVE-2025-63034

Description

Missing Authorization vulnerability in Steve Truman Page View Count page-views-count allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Page View Count: from n/a through <= 2.9.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Page View Count ≤2.9.0 lets unauthenticated attackers change plugin settings, enabling mass-exploit campaigns.

Vulnerability

Overview

The Page View Count plugin for WordPress plugin (page-views-count) versions up to and including 2.9.0 contain a Missing Authorization vulnerability [1]. This flaw allows an attacker to exploit incorrectly configured access control security levels, effectively bypassing intended permission checks [1].

Exploitation

Details

The vulnerability is classified as a Settings Change issue, meaning an unauthenticated remote attacker can modify the plugin's configuration without any prior authentication or elevated privileges or user interaction. The attack surface is broad because the plugin is widely used, and the exploit does not require a privileged account or complex network position [1].

Impact

Successful exploitation enables an attacker to alter plugin settings arbitrarily alter the plugin's settings, potentially redirecting page view tracking or potentially injecting malicious content. This type of vulnerability is frequently leveraged in mass-exploit campaigns targeting thousands of WordPress sites simultaneously, regardless of site size or popularity [1].

Mitigation

The vendor has notifies that immediate action is required: update the plugin to a patched version beyond 2.9.0. If an update is not possible, users should contact their hosting provider or web developer for assistance. No workaround is provided beyond updating [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.