CVE-2026-15361: Unknown Content Views

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.

Affected products

  • Unknown Content Views: before 4.5 (fixed in 4.5)

Published 2026-08-07. Last modified 2026-08-26.