# Post Views Counter <= 1.7.15 - Authenticated (Contributor+) Missing Authorization to Sensitive Information Exposure via pvc_column_chart AJAX Action

- **ID:** WPSEC-2026-0767
- **Plugin:** Post Views Counter (`post-views-counter`), https://wordpress.org/plugins/post-views-counter/
- **Affected versions:** from 1.5.9 before 1.8.0
- **Fixed in:** 1.8.0 (Update to 1.8.0 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin High, affected versions High (as of 2026-10-11)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/post-views-counter
- **Fix released:** 2026-10-08
- **Published:** 2026-10-11
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0767/

## Description

The Post Views Counter plugin for WordPress is vulnerable to unauthorized access of data via the 'pvc_column_chart' AJAX action in all versions from 1.5.9 up to, and including, 1.7.15, due to a missing capability check in the ajax_column_chart() function. The handler checked only a nonce, and that nonce is printed on every post list screen. It did not check whether the current user could read the requested post. This makes it possible for authenticated attackers with contributor-level access and above to read the title and daily view statistics of any tracked post, including private posts and drafts belonging to other users.

## References

- https://wpsec.com/vuln/WPSEC-2026-0767/
- https://plugins.svn.wordpress.org/post-views-counter/tags/1.8.0/
- https://wordpress.org/plugins/post-views-counter/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0767/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
