CVE-2025-14609
Wise Analytics <= 1.1.9 - Missing Authorization to Unauthenticated Arbitrary Analytics Database Disclosure via 'name' Parameter
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.9. This is due to missing capability checks on the REST API endpoint '/wise-analytics/v1/report'. This makes it possible for unauthenticated attackers to access sensitive analytics data including administrator usernames, login timestamps, visitor tracking information, and business intelligence data via the 'name' parameter granted they can send unauthenticated requests.
| CWE | CWE-862 |
| Vendor | marcinlawrowski |
| Product | wise analytics |
| Published | Jan 24, 2026 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for marcinlawrowski wise analytics
Be the first to know when new medium vulnerabilities affecting marcinlawrowski wise analytics are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
marcinlawrowski / Wise Analytics
0 โค 1.1.9
References
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/d92c80cb-080b-4774-8c66-1d5cf68e771f?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wise-analytics/trunk/src/Endpoints/ReportsEndpoint.php#L43 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/wise-analytics/tags/1.1.9/src/Endpoints/ReportsEndpoint.php#L43 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3446670/
Credits
Lior Yeshayahu