CVE-2026-16562
Received Received - Intake

WP Statistics Visitor Analytics Exposure via Missing Capability Check

Vulnerability report for CVE-2026-16562, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-08

Last updated on: 2026-08-08

Assigner: WPScan

Description

The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-08
Last Modified
2026-08-08
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wp_statistics wp_statistics to 14.16.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WP Statistics WordPress plugin versions before 14.16.10. It allows authenticated users with Subscriber-level access or higher to access sensitive visitor analytics data due to missing capability checks on certain dashboard analytics AJAX handlers. The plugin only verifies a nonce that all authenticated users have, which is insufficient for proper authorization.

Detection Guidance

To detect this vulnerability, check if your WP Statistics plugin version is below 14.16.10. You can use WordPress admin dashboard or run commands like 'wp plugin list' in WP-CLI to verify the installed version.

Impact Analysis

If you use the affected WP Statistics plugin, an attacker with Subscriber access or higher could view your site's visitor analytics data. This includes sensitive information about site traffic, user behavior, and potentially other tracked metrics, leading to privacy and security risks.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if visitor analytics data includes personally identifiable information (PII). Unauthorized access to such data violates privacy regulations, potentially resulting in legal penalties, fines, or reputational damage for organizations handling sensitive user data.

Mitigation Strategies

Immediately update the WP Statistics plugin to version 14.16.10 or later to address the capability check issue and prevent unauthorized access to visitor analytics data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16562. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart