Junglewise Threat Intelligence

CVE-2026-81795: WordPress Page Visits Counter , Lite unauthenticated XSS

CVE-2026-81795 · Severity: high · CVSS 7.1 · Published 2026-09-10

Vendors: Wordpress.

Executive brief

Page Visits Counter – Lite is a WordPress plugin that tracks and displays page view statistics on websites. Versions up to 1.2.3 contain an unauthenticated cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into pages without requiring login credentials. An attacker could exploit this to steal visitor data, hijack user accounts, or compromise site functionality.

Technical details

The vulnerability is an unauthenticated cross-site scripting (XSS) flaw in the Page Visits Counter – Lite WordPress plugin affecting versions 1.2.3 and earlier. The vulnerability allows attackers to inject malicious scripts that execute in the context of the affected website without requiring authentication. While user interaction is required (such as clicking a malicious link or visiting a crafted page), the unauthenticated nature means any visitor can be targeted. The vulnerability has a CVSS score of 7.1 (high severity). The plugin was patched in version 2.0.0, which users should upgrade to immediately.

Affected products

  • WordPress Page Visits Counter – Lite <=1.2.3

Timeline

  • 2026-04-06: disclosed: Reported to Patchstack by Nguyen Ba Khanh - HPT Vietnam Corporation
  • 2026-09-08: advisory: Patchstack advisory published
  • 2026-09-10: other: CVE-2026-81795 published on NVD

References