Post Views Counter <= 1.7.15 - Authenticated (Contributor+) Missing Authorization to Post View Count Modification via REST API
- ID
- WPSEC-2026-0768
- Plugin
- Post Views Counter (post-views-counter)
- Affected
- all versions before 1.8.0
- Remediation
- Update to 1.8.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-863
- Usage
- Plugin High · Affected versions High among sites WPSec scans, 2026-10-11
- Attack surface
- Post Views Counter on WPSec AttackSurface
- Fix released
- Published
Description
The Post Views Counter plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.7.15 due to an incorrect authorization check on the block editor 'post-views-counter/update-post-views' REST route. The route only required the edit_post capability and enforced the restricted capability (manage_options by default) only when manual view editing was enabled, so the check was skipped when editing was disabled. This makes it possible for authenticated attackers with contributor-level access and above to set arbitrary view counts on posts they can edit, manipulating statistics and popularity rankings.
References
- https://wpsec.com/vuln/WPSEC-2026-0768/
- https://plugins.svn.wordpress.org/post-views-counter/tags/1.8.0/
- https://wordpress.org/plugins/post-views-counter/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS