# Post Views Counter <= 1.7.15 - Authenticated (Contributor+) Missing Authorization to Post View Count Modification via REST API

- **ID:** WPSEC-2026-0768
- **Plugin:** Post Views Counter (`post-views-counter`), https://wordpress.org/plugins/post-views-counter/
- **Affected versions:** all versions before 1.8.0
- **Fixed in:** 1.8.0 (Update to 1.8.0 or later.)
- **Severity:** Medium 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-863
- **Usage among sites WPSec scans:** plugin High, affected versions High (as of 2026-10-11)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/post-views-counter
- **Fix released:** 2026-10-08
- **Published:** 2026-10-11
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0768/

## Description

The Post Views Counter plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.7.15 due to an incorrect authorization check on the block editor 'post-views-counter/update-post-views' REST route. The route only required the edit_post capability and enforced the restricted capability (manage_options by default) only when manual view editing was enabled, so the check was skipped when editing was disabled. This makes it possible for authenticated attackers with contributor-level access and above to set arbitrary view counts on posts they can edit, manipulating statistics and popularity rankings.

## References

- https://wpsec.com/vuln/WPSEC-2026-0768/
- https://plugins.svn.wordpress.org/post-views-counter/tags/1.8.0/
- https://wordpress.org/plugins/post-views-counter/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0768/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
