VYPR

Content Views

by WordPress

CVEs (2)

  • CVE-2026-15361HigAug 7, 2026
    risk 0.53cvss 8.1epss 0.00

    The Content Views WordPress plugin before 4.5 does not perform a capability check on one of its AJAX actions and does not properly sanitise attacker-supplied data before using it in a SQL query, allowing any authenticated user, including Subscribers, to perform SQL injection…

  • CVE-2025-8722MedSep 6, 2025
    risk 0.35cvss 6.4epss 0.00

    The Content Views plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Grid and List widgets in all versions up to, and including, 4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…