Feed/CVE-2026-16562
CVE-2026-16562MEDIUMCVSS 6.5

CVE-2026-16562

Published Aug 8, 2026·Updated Aug 10, 2026

NVD Description

The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free