CyberRota Analysis
AI-GeneratedThe WP Statistics plugin for WordPress prior to version 14.16.10 is vulnerable due to inadequate capability checks on certain AJAX handlers, allowing authenticated users with Subscriber-level access and higher to access sensitive visitor analytics data. This exposure could lead to unauthorized disclosure of site traffic information, potentially compromising user privacy and site security. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of data leakage.
Original NVD Description
The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.