ZeroHour

CVE-2026-81795

moderate

Unauthenticated XSS in Page Visits Counter – Lite WordPress Plugin

CVSS 3.1
7.1 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-81795 is an unauthenticated cross-site scripting (XSS, CWE-79) flaw in the Page Visits Counter – Lite WordPress plugin, affecting all versions up to and including 1.2.3. Because the flaw requires no authentication or special privileges (CVSS PR:N), an unauthenticated attacker can send a crafted request to a site running the plugin that causes attacker-controlled JavaScript to execute in the browser of another user, most plausibly an administrator viewing plugin-related data; per the CVSS vector (UI:R), the payload requires the victim to interact with an affected page. Since the scripting executes in the victim's own session (scope change), the attacker can act as that user — for example performing admin actions or accessing data visible to them — with low impact across confidentiality, integrity, and availability reflected in the 7.1 (High) CVSS score. Any WordPress site running Page Visits Counter – Lite version 1.2.3 or earlier is affected. No public proof-of-concept is known and the flaw is not listed in CISA's KEV, with no confirmed in-the-wild exploitation reported.

What to do: Update Page Visits Counter – Lite to the latest available patched release (any version above 1.2.3) as soon as possible; if updating is not immediately possible, deactivate the plugin as an interim mitigation. Administrators should also review recent admin activity and site changes for signs of compromise, though no in-the-wild exploitation is currently known.

Affected
wp-buy Page Visits Counter – Lite (WordPress plugin)<= 1.2.3
Estimated exposure
moderate≈10,000 WordPress sites (plugin's active-install count is on the order of ten thousand) — Estimated from the plugin's modest active-install base on the WordPress.org directory, indicating roughly ten thousand deployments, all of which are affected if still running version 1.2.3 or earlier.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.