CVE-2026-81795: WordPress Page Visits Counter – Lite plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnerability
Published Sep 10, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter – Lite <= 1.2.3 versions.
Affected Software
1 affected component
wordpress/plugin/page-visits-counter-lite<=1.2.3
Event History
Sep 10, 2026
CVE Published
via MITRE·02:23 PM
Data Sourced
via MITRE·02:23 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as unauthenticated XSS, so an attacker does not need a WordPress account or plugin privileges to attempt exploitation. The CVSS vector indicates network access and low attack complexity, but requires user interaction.
2
What is the known affected version range?
Page Visits Counter – Lite version 1.2.3 and earlier are identified as affected. The provided information does not state a fixed version.
3
What is the potential impact if exploitation succeeds?
The supplied CVSS vector indicates low confidentiality, integrity, and availability impact, with scope changed. Because exploitation requires user interaction, a victim would need to interact with attacker-controlled content or a crafted request for the XSS to take effect.