External initialization of trusted variables or data...
High severity
Unreviewed
Published
Dec 7, 2022
to the GitHub Advisory Database
•
Updated Apr 23, 2025
Description
Published by the National Vulnerability Database
Dec 7, 2022
Published to the GitHub Advisory Database
Dec 7, 2022
Last updated
Apr 23, 2025
External initialization of trusted variables or data stores vulnerability exists in WordPress Popular Posts 6.0.5 and earlier, therefore the vulnerable product accepts untrusted external inputs to update certain internal variables. As a result, the number of views for an article may be manipulated through a crafted input.
References