CVE-2026-16562: Unknown Wp Statistics
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.
Affected products
- Unknown Wp Statistics: before 14.16.10 (fixed in 14.16.10)
Published 2026-08-08. Last modified 2026-08-26.