CVE-2026-15361: Unknown Content Views
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.
Affected products
- Unknown Content Views: before 4.5 (fixed in 4.5)
Published 2026-08-07. Last modified 2026-08-26.