๐Ÿ” CVE Alert

CVE-2026-15361

UNKNOWN 0.0

Content Views < 4.5 - Subscriber+ SQL Injection via preview_request

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.

Vendor unknown
Product content views
Published Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for unknown content views

Be the first to know when new unknown vulnerabilities affecting unknown content views are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Content Views
0 < 4.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/3fa62b23-a0a7-4b42-b8dd-0eb6e01972b2/

Credits

Jakub Herman WPScan