Executive brief
The WP Promoter plugin for WordPress, which is used to manage promotional bars and popups, contains a security flaw that allows unauthorized users to reset plugin statistics. An attacker can remotely delete the data tracking how many times promotional bars and popups have been viewed or interacted with. This results in the loss of marketing analytics and can disrupt business reporting on website engagement.
Technical details
The WP Promoter plugin for WordPress is vulnerable to an authorization bypass in the reset_stats() function. The vulnerability exists because the function is hooked to both wp_ajax_wpp-reset_stats and wp_ajax_nopriv_wpp-reset_stats actions without any capability checks, authentication, or nonce validation. A remote, unauthenticated attacker can exploit this by sending a crafted AJAX request to the WordPress site. Successful exploitation allows the attacker to delete the wpp_bar and wpp_popup options from the database, effectively resetting the plugin's promotional statistics. This issue affects all versions of the plugin up to and including 1.3.
Affected products
- WP Promoter WP Promoter up to, and including, 1.3
Timeline
- 2026-05-27: disclosed: Vulnerability published by Wordfence and NVD.