AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16562

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-08 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The WP Statistics plugin for WordPress prior to version 14.16.10 is vulnerable due to inadequate capability checks on certain AJAX handlers, allowing authenticated users with Subscriber-level access and higher to access sensitive visitor analytics data. This exposure could lead to unauthorized disclosure of site traffic information, potentially compromising user privacy and site security. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of data leakage.

CVE
CVE-2026-16562
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%
WordPress

Original NVD Description

The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.