{
 "id": "WPSEC-2026-0767",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0767/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0767/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0767/index.md",
 "title": "Post Views Counter <= 1.7.15 - Authenticated (Contributor+) Missing Authorization to Sensitive Information Exposure via pvc_column_chart AJAX Action",
 "description": "The Post Views Counter plugin for WordPress is vulnerable to unauthorized access of data via the 'pvc_column_chart' AJAX action in all versions from 1.5.9 up to, and including, 1.7.15, due to a missing capability check in the ajax_column_chart() function. The handler checked only a nonce, and that nonce is printed on every post list screen. It did not check whether the current user could read the requested post. This makes it possible for authenticated attackers with contributor-level access and above to read the title and daily view statistics of any tracked post, including private posts and drafts belonging to other users.",
 "plugin": {
  "slug": "post-views-counter",
  "name": "Post Views Counter",
  "full_name": "Post Views Counter",
  "wordpress_org": "https://wordpress.org/plugins/post-views-counter/",
  "advisories_url": "https://wpsec.com/vuln/plugin/post-views-counter/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/post-views-counter"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": "1.5.9",
    "from_inclusive": true,
    "to": "1.8.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 1.5.9 before 1.8.0"
  ]
 },
 "introduced_in": "1.5.9",
 "fixed_in": "1.8.0",
 "remediation": "Update to 1.8.0 or later.",
 "fix_released": "2026-10-08T09:17:45+00:00",
 "published": "2026-10-11T12:43:38+00:00",
 "updated": "2026-10-11T11:37:57.963022+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0767/",
  "https://plugins.svn.wordpress.org/post-views-counter/tags/1.8.0/",
  "https://wordpress.org/plugins/post-views-counter/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/post-views-counter",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "High",
  "affected_versions": "High",
  "as_of": "2026-10-11"
 }
}