CVE-2025-55716: WordPress WP Statistics Plugin <= 14.15 - Broken Access Control Vulnerability
Missing Authorization vulnerability in VeronaLabs WP Statistics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Statistics: from n/a through 14.15.
Other sources
Missing Authorization vulnerability in VeronaLabs WP Statistics wp-statistics allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Statistics: from n/a through <= 14.15.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55716?
CVE-2025-55716 is considered a high severity vulnerability due to missing authorization allowing exploitation of access control security settings.
How do I fix CVE-2025-55716?
To fix CVE-2025-55716, update the WP Statistics plugin to version 14.16 or later.
Which versions of WP Statistics are affected by CVE-2025-55716?
CVE-2025-55716 affects WP Statistics versions up to and including 14.15.
What type of vulnerability is CVE-2025-55716?
CVE-2025-55716 is categorized as a Missing Authorization vulnerability.
What can an attacker do with CVE-2025-55716?
An attacker exploiting CVE-2025-55716 can gain unauthorized access to sensitive areas of the WP Statistics plugin.