CVE-2026-15361: Content Views < 4.5 - Subscriber+ SQL Injection via preview_request
The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15361?
CVE-2026-15361 has a risk score of 70, indicating a significant level of vulnerability.
How do I fix CVE-2026-15361?
To fix CVE-2026-15361, update the Content Views WordPress plugin to version 4.5 or later.
Who is affected by CVE-2026-15361?
CVE-2026-15361 affects all versions of the Content Views WordPress plugin prior to 4.5 used by authenticated users including Subscribers.
What type of vulnerability is CVE-2026-15361?
CVE-2026-15361 is classified as an SQL Injection vulnerability.
What are the consequences of exploiting CVE-2026-15361?
Exploiting CVE-2026-15361 can allow an attacker to perform unauthorized SQL manipulation, potentially compromising the database.