PT-2026-69174 · WordPress · Wp Statistics

·

CVE-2026-16562

·

Published

2026-08-08

·

Updated

2026-08-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Statistics versions prior to 14.16.10
Description Insufficient capability checks in a set of dashboard analytics AJAX handlers allow authenticated users with Subscriber-level access and above to disclose sensitive site visitor analytics data. The system relies solely on a nonce, which is a unique token used to prevent cross-site request forgery, but since every authenticated user possesses one, it fails to restrict access based on user roles.
Recommendations Update WP Statistics to version 14.16.10 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16562

Affected Products

Wp Statistics