CVE-2026-16562: CWE-200 Information Exposure in WP Statistics
The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.
AI Analysis
Technical Summary
The WP Statistics plugin versions prior to 14.16.10 do not enforce capability checks on some AJAX handlers used for dashboard analytics. Instead, they rely only on a nonce, which is available to all authenticated users regardless of their privilege level. As a result, users with low-level privileges (Subscriber and above) can retrieve sensitive visitor analytics data, leading to an information disclosure vulnerability classified as CWE-200.
Potential Impact
The vulnerability allows unauthorized disclosure of visitor analytics data to users with Subscriber-level access or higher. This exposure could lead to privacy concerns or leakage of sensitive site traffic information. There is no indication of impact on integrity or availability.
Mitigation Recommendations
No official patch or remediation guidance is currently confirmed. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, site administrators should consider restricting access to the affected AJAX handlers or limiting Subscriber-level user capabilities as a temporary mitigation.
CVE-2026-16562: CWE-200 Information Exposure in WP Statistics
Description
The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.
CVSS v3.1
Score 6.5medium
Affected software
WP Statistics
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The WP Statistics plugin versions prior to 14.16.10 do not enforce capability checks on some AJAX handlers used for dashboard analytics. Instead, they rely only on a nonce, which is available to all authenticated users regardless of their privilege level. As a result, users with low-level privileges (Subscriber and above) can retrieve sensitive visitor analytics data, leading to an information disclosure vulnerability classified as CWE-200.
Potential Impact
The vulnerability allows unauthorized disclosure of visitor analytics data to users with Subscriber-level access or higher. This exposure could lead to privacy concerns or leakage of sensitive site traffic information. There is no indication of impact on integrity or availability.
Mitigation Recommendations
No official patch or remediation guidance is currently confirmed. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, site administrators should consider restricting access to the affected AJAX handlers or limiting Subscriber-level user capabilities as a temporary mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-22T12:27:00.681Z
- State
- PUBLISHED
Threat ID: 6a76cc2abf8831d539114715
Added to database: 08/08/2026, 06:26:50 UTC
Last enriched: 08/15/2026, 15:11:43 UTC
Last updated: 09/22/2026, 01:52:42 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.