CVE · High

CVE-2026-5464 — ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) [google-analytics-dashboard-for-wp] < 9.1.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-5464 ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) [google-analytics-dashboard-for-wp] < 9.1.3 Missing Authorization High 7.2 < 9.1.3 9.1.3 2026-04-22

CVE-2026-5464

The ExactMetrics WordPress plugin has a security flaw affecting versions up to 9.1.2. A specific capability allows users with elevated permissions to view reports to access a sensitive authorization key, which is the sole check for a REST endpoint that returns a one-time token used for plugin installation and activation. This lack of proper verification enables attackers with Editor-level access or higher to install and activate malicious plugins from arbitrary URLs, potentially leading to code execution on remote servers.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.