Junglewise Threat Intelligence

CVE-2026-16562: WP Statistics sensitive data disclosure in dashboard AJAX handlers

CVE-2026-16562 · Severity: medium · CVSS 6.5 · Published 2026-08-08

Executive brief

WP Statistics is a WordPress plugin that tracks and displays visitor analytics on site dashboards. A flaw allows any logged-in user with Subscriber-level access to view sensitive analytics data including visitor referrers, geolocation, page views, and browser information, bypassing intended access restrictions. This exposes business-critical traffic intelligence to low-privileged accounts.

Technical details

The plugin fails to perform proper WordPress capability checks on multiple AJAX handlers that return dashboard metabox analytics data (wp_statistics_recent_metabox_get_data, wp_statistics_referring_metabox_get_data, and others). Instead, authentication relies solely on a nonce (wp_rest) that is available to all authenticated users. An attacker with Subscriber-level or higher access can call these handlers directly with a valid nonce to retrieve detailed analytics including referrer URLs, visitor geolocation, page views, timestamps, browser data, and active visitor information. The vulnerability is network-accessible via wp-admin/admin-ajax.php and requires only valid WordPress authentication credentials.

Affected products

  • Jegstudio WP Statistics before 14.16.10

Timeline

  • 2026-08-03: disclosed
  • 2026-08-08: advisory

References