CVE-2025-3953: WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin <= 14.13.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Update
The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'optionUpdater' function in all versions up to, and including, 14.13.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary plugin settings.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3953?
CVE-2025-3953 has a high severity rating due to unauthorized data modification risks.
What is CVE-2025-3953 about?
CVE-2025-3953 involves a missing capability check vulnerability in the WP Statistics plugin for WordPress.
How do I fix CVE-2025-3953?
To fix CVE-2025-3953, update the WP Statistics plugin to version 14.13.4 or later.
Who is affected by CVE-2025-3953?
All users of the WP Statistics plugin up to and including version 14.13.3 are affected by CVE-2025-3953.
What can happen if CVE-2025-3953 is exploited?
Exploitation of CVE-2025-3953 can lead to unauthorized modification of analytics data.