Impact
The Content Views WordPress plugin, in all releases prior to 4.5.1.2, fails to enforce permission checks on the posts returned by a view. When a view has been configured to include non‑public post statuses, the plugin exposes the title and full content of draft, pending, private, or scheduled posts to any visitor, regardless of authentication status. This results in the disclosure of material that was intended to be confidential or only available to authorized users.
Affected Systems
WordPress installations that have the Content Views plugin installed with a version earlier than 4.5.1.2 and that have at least one view configured to include status values such as draft, pending, private, or scheduled. The vendor is not clearly identified beyond the plugin name, and the plugin is commonly present in public site repositories.
Risk and Exploitability
The flaw can be exploited from a remote host by issuing a standard HTTP request to a configured view endpoint. No authentication is required, and the vulnerability does not require any special privileges or knowledge of site internals; the attack vector is inferred from the description. The CVSS score is 5.3, indicating a medium impact rating. The EPSS score of < 1% shows that exploitation is unlikely but possible, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment