GHSA-gp8v-vc4r-wpf4HighCVSS 8.1

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its...

Published
August 7, 2026
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.

🔗 References (3)