Access Control Vulnerability in AJAX Hits Counter and Popular Posts Widget by Kutsy
CVE-2026-24587
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 January 2026
What is CVE-2026-24587?
The AJAX Hits Counter + Popular Posts Widget by Kutsy is susceptible to a missing authorization flaw due to improperly configured access control security levels. This vulnerability allows unauthorized users to exploit the system, potentially leading to unauthorized access and manipulation of sensitive data. Users running versions up to 0.10.210305 should prioritize updating their plugins to mitigate associated risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AJAX Hits Counter + Popular Posts Widget <= n/a
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Nabil Irawan | Patchstack Bug Bounty Program