What is CVE-2026-16562?
CVE-2026-16562: The WP Statistics WordPress plugin before version 14.16.10 lacks proper capability checks on dashboard analytics AJAX handlers, relying solely on a nonce available to all authenticated users, allowing Subscriber-level users to disclose the site's visitor analytics data. Updating to the latest version is recommended.
Azərbaycanca: CVE-2026-16562: WP Statistics WordPress plaginində 14.16.10 versiyasından əvvəl dashboard analitika AJAX idarəedicilərində yetərli icazə yoxlaması aparılmır, yalnız hər bir autentifikasiya olunmuş istifadəçidə olan nonce-ə etibar edilir ki, bu da Subscriber səviyyəli istifadəçilərə saytın ziyarətçi analitika məlumatlarını ifşa etməyə imkan verir. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the WP Statistics plugin are affected by CVE-2026-16562, and which user level can disclose site analytics?
The vulnerability affects the WP Statistics plugin before version 14.16.10. Subscriber-level users can disclose the site's visitor analytics data due to insufficient capability checks on dashboard analytics AJAX handlers.
What should WP Statistics plugin owners do to protect against CVE-2026-16562?
Plugin owners should update WP Statistics to the latest version, i.e., 14.16.10 or higher, to fix the insufficient capability checks on dashboard analytics AJAX handlers.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.