Impact
Unauthenticated Cross Site Scripting (XSS) exists in Page Visits Counter – Lite versions up to 1.2.3. The flaw allows injection of arbitrary JavaScript when a page displays the visit counter. The injected script runs in the context of the site, potentially affecting site functionality.
Affected Systems
The vulnerability affects WordPress installations running the Denis Botić:Page Visits Counter – Lite plugin version 1.2.3 or earlier. The plugin’s counter displays visitor statistics on site pages.
Risk and Exploitability
Attack execution does not require authentication and relies on a user accessing a page where the counter is rendered; therefore anyone who can view the site could potentially trigger the payload. The CVSS score of 7.1 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog.
OpenCVE Enrichment