{
 "id": "WPSEC-2026-0768",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0768/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0768/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0768/index.md",
 "title": "Post Views Counter <= 1.7.15 - Authenticated (Contributor+) Missing Authorization to Post View Count Modification via REST API",
 "description": "The Post Views Counter plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.7.15 due to an incorrect authorization check on the block editor 'post-views-counter/update-post-views' REST route. The route only required the edit_post capability and enforced the restricted capability (manage_options by default) only when manual view editing was enabled, so the check was skipped when editing was disabled. This makes it possible for authenticated attackers with contributor-level access and above to set arbitrary view counts on posts they can edit, manipulating statistics and popularity rankings.",
 "plugin": {
  "slug": "post-views-counter",
  "name": "Post Views Counter",
  "full_name": "Post Views Counter",
  "wordpress_org": "https://wordpress.org/plugins/post-views-counter/",
  "advisories_url": "https://wpsec.com/vuln/plugin/post-views-counter/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/post-views-counter"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-863"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 4.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.8.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.8.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.8.0",
 "remediation": "Update to 1.8.0 or later.",
 "fix_released": "2026-10-08T09:17:45+00:00",
 "published": "2026-10-11T12:43:38+00:00",
 "updated": "2026-10-11T11:37:57.963022+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0768/",
  "https://plugins.svn.wordpress.org/post-views-counter/tags/1.8.0/",
  "https://wordpress.org/plugins/post-views-counter/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/post-views-counter",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "High",
  "affected_versions": "High",
  "as_of": "2026-10-11"
 }
}