CVE-2026-81795
moderateUnauthenticated XSS in Page Visits Counter – Lite WordPress Plugin
CVE-2026-81795 is an unauthenticated cross-site scripting (XSS, CWE-79) flaw in the Page Visits Counter – Lite WordPress plugin, affecting all versions up to and including 1.2.3. Because the flaw requires no authentication or special privileges (CVSS PR:N), an unauthenticated attacker can send a crafted request to a site running the plugin that causes attacker-controlled JavaScript to execute in the browser of another user, most plausibly an administrator viewing plugin-related data; per the CVSS vector (UI:R), the payload requires the victim to interact with an affected page. Since the scripting executes in the victim's own session (scope change), the attacker can act as that user — for example performing admin actions or accessing data visible to them — with low impact across confidentiality, integrity, and availability reflected in the 7.1 (High) CVSS score. Any WordPress site running Page Visits Counter – Lite version 1.2.3 or earlier is affected. No public proof-of-concept is known and the flaw is not listed in CISA's KEV, with no confirmed in-the-wild exploitation reported.
What to do: Update Page Visits Counter – Lite to the latest available patched release (any version above 1.2.3) as soon as possible; if updating is not immediately possible, deactivate the plugin as an interim mitigation. Administrators should also review recent admin activity and site changes for signs of compromise, though no in-the-wild exploitation is currently known.
| wp-buy Page Visits Counter – Lite (WordPress plugin) | <= 1.2.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.