Executive brief
WP Statistics is a WordPress plugin that tracks and displays visitor analytics on site dashboards. A flaw allows any logged-in user with Subscriber-level access to view sensitive analytics data including visitor referrers, geolocation, page views, and browser information, bypassing intended access restrictions. This exposes business-critical traffic intelligence to low-privileged accounts.
Technical details
The plugin fails to perform proper WordPress capability checks on multiple AJAX handlers that return dashboard metabox analytics data (wp_statistics_recent_metabox_get_data, wp_statistics_referring_metabox_get_data, and others). Instead, authentication relies solely on a nonce (wp_rest) that is available to all authenticated users. An attacker with Subscriber-level or higher access can call these handlers directly with a valid nonce to retrieve detailed analytics including referrer URLs, visitor geolocation, page views, timestamps, browser data, and active visitor information. The vulnerability is network-accessible via wp-admin/admin-ajax.php and requires only valid WordPress authentication credentials.
Affected products
- Jegstudio WP Statistics before 14.16.10
Timeline
- 2026-08-03: disclosed
- 2026-08-08: advisory