PT-2026-85407 · WordPress · Content Views

CVE-2026-17517

·

Published

2026-09-04

·

Updated

2026-09-04

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Content Views versions prior to 4.5.1.2
Description The Content Views WordPress plugin fails to verify if the user requesting a view has the necessary permissions to read the returned posts. This allows unauthenticated attackers to access the title and content of non-public posts, including those with draft, pending, private, or scheduled status, provided the view is configured to include them.
Recommendations Update Content Views to version 4.5.1.2 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17517

Affected Products

Content Views