Vulnerability Description
The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.
References
FAQ
What is CVE-2026-16562?
CVE-2026-16562 is a documented vulnerability. The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allo...
How severe is CVE-2026-16562?
CVSS scoring is not yet available for CVE-2026-16562. Check NVD for updates.
Is there a patch for CVE-2026-16562?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.