CVE-2026-16562 PUBLISHED

WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers

Assigner: WPScan
Reserved: 22.07.2026 Published: 08.08.2026 Updated: 08.08.2026

The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.

Product Status

Vendor Unknown
Product WP Statistics
Versions Default: unaffected
  • affected from 0 to 14.16.10 (excl.)

Credits

  • Shivamani Vastrala finder
  • WPScan coordinator

References

Problem Types

  • CWE-200 Information Exposure CWE