Post Views Counter <= 1.7.15 - Authenticated (Contributor+) Missing Authorization to Post View Count Modification via REST API

Medium 4.3 CWE-863Fixed in 1.8.0
ID
WPSEC-2026-0768
Plugin
Post Views Counter (post-views-counter)
Affected
all versions before 1.8.0
Remediation
Update to 1.8.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-863
Usage
Plugin High · Affected versions High among sites WPSec scans, 2026-10-11
Attack surface
Post Views Counter on WPSec AttackSurface
Fix released
Published

Description

The Post Views Counter plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.7.15 due to an incorrect authorization check on the block editor 'post-views-counter/update-post-views' REST route. The route only required the edit_post capability and enforced the restricted capability (manage_options by default) only when manual view editing was enabled, so the check was skipped when editing was disabled. This makes it possible for authenticated attackers with contributor-level access and above to set arbitrary view counts on posts they can edit, manipulating statistics and popularity rankings.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0