{"id":"CVE-2026-16562","title":"The WP Statistics  WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level acce…","summary":"The WP Statistics  WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level acce…","severity":"none","published":"2026-08-08","updated":"2026-08-08","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-16562","references":[{"url":"https://wpscan.com/vulnerability/09d79a3f-7bf0-47ab-bf6d-913eaeb71630/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00219,"epssPercentile":0.12611,"ingestedAt":"2026-08-09T03:32:40.366Z","slug":"CVE-2026-16562","body":"## Overview\n\nThe WP Statistics  WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}