CVE Database /
CVE-2026-3488
CVE · Medium
CVE-2026-3488 — WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.16.5
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-3488
|
WP Statistics – Simple, privacy-friendly Google Analytics alternative [wp-statistics] < 14.16.5 |
Missing Authorization |
Medium
6.5
|
< 14.16.5
|
14.16.5 |
2026-04-16 |
—
|
CVE-2026-3488
The WP Statistics plugin for WordPress contains a flaw in versions up to 14.16.4 that allows unauthorized access to sensitive user information and analytics data. This vulnerability arises from the failure of multiple AJAX handlers to verify user permissions before processing requests. As a result, authenticated users with Subscriber-level access or higher can exploit this weakness to obtain confidential details about visitors and modify privacy settings.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings