CVE-2026-16562
WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers
CVSS Score
6.5
EPSS Score
0.1%
EPSS Percentile
4th
The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.
| Vendor | unknown |
| Product | wp statistics |
| Published | Aug 8, 2026 |
| Last Updated | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp statistics
Be the first to know when new medium vulnerabilities affecting unknown wp statistics are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Statistics
0 < 14.16.10
References
Credits
Shivamani Vastrala WPScan