CVE-2026-16562: Unknown Wp Statistics

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.

Affected products

  • Unknown Wp Statistics: before 14.16.10 (fixed in 14.16.10)

Published 2026-08-08. Last modified 2026-08-26.