CVE-2026-16562: WP Statistics < 14.16.10 - Subscriber+ Sensitive Data Disclosure via Metabox AJAX Handlers
The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16562?
CVE-2026-16562 has a risk rating of 35, indicating a moderate severity level due to potential sensitive data disclosure.
How do I fix CVE-2026-16562?
To address CVE-2026-16562, update the WP Statistics plugin to version 14.16.10 or later, which includes necessary security enhancements.
What type of data is exposed by CVE-2026-16562?
CVE-2026-16562 allows unauthorized disclosure of the site's visitor analytics data, which may compromise sensitive information.
Who is affected by CVE-2026-16562?
CVE-2026-16562 affects any user with Subscriber-level access or higher on sites using versions of the WP Statistics plugin before 14.16.10.
When was CVE-2026-16562 published?
CVE-2026-16562 was published on August 8, 2026.