Post Views Counter <= 1.7.15 - Authenticated (Contributor+) Missing Authorization to Sensitive Information Exposure via pvc_column_chart AJAX Action

Medium 4.3 CWE-862Fixed in 1.8.0
ID
WPSEC-2026-0767
Plugin
Post Views Counter (post-views-counter)
Affected
from 1.5.9 before 1.8.0
Remediation
Update to 1.8.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-862
Usage
Plugin High · Affected versions High among sites WPSec scans, 2026-10-11
Attack surface
Post Views Counter on WPSec AttackSurface
Fix released
Published

Description

The Post Views Counter plugin for WordPress is vulnerable to unauthorized access of data via the 'pvc_column_chart' AJAX action in all versions from 1.5.9 up to, and including, 1.7.15, due to a missing capability check in the ajax_column_chart() function. The handler checked only a nonce, and that nonce is printed on every post list screen. It did not check whether the current user could read the requested post. This makes it possible for authenticated attackers with contributor-level access and above to read the title and daily view statistics of any tracked post, including private posts and drafts belonging to other users.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0