What is CVE-2026-15361?
CVE-2026-15361 affects the 'Content Views' WordPress plugin before version 4.5. It allows any authenticated user, including Subscribers, to perform SQL injection attacks due to a missing capability check on an AJAX action and improper sanitization of attacker-supplied data. Updating the plugin to the latest version is recommended.
Azərbaycanca: CVE-2026-15361, 'Content Views' WordPress plaginin 4.5 versiyasından əvvəlki versiyalarında aşkar edilmişdir. Autentifikasiya olunmuş istənilən istifadəçiyə (o cümlədən Subscribers) SQL injection hücumu etməyə imkan verir, çünki AJAX əməliyyatında capability check və verilənlərin sanitizasiyası düzgün aparılmır. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Which versions of the 'Content Views' plugin are affected by CVE-2026-15361?
This vulnerability affects the 'Content Views' WordPress plugin in versions before 4.5.
What level of privilege is required to exploit CVE-2026-15361?
Any authenticated user, including Subscribers, can perform this SQL injection attack.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.