---
id: CVE-2026-16562
title: >-
  The WP Statistics  WordPress plugin before 14.16.10 does not perform a
  capability check on a set of dashboard analytics AJAX handlers, relying only
  on a nonce that every authenticated user holds, allowing users with
  Subscriber-level acce…
summary: >-
  The WP Statistics  WordPress plugin before 14.16.10 does not perform a
  capability check on a set of dashboard analytics AJAX handlers, relying only
  on a nonce that every authenticated user holds, allowing users with
  Subscriber-level acce…
severity: none
published: '2026-08-08'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16562'
references:
  - url: 'https://wpscan.com/vulnerability/09d79a3f-7bf0-47ab-bf6d-913eaeb71630/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00371
epssPercentile: 0.28247
ingestedAt: '2026-08-09T03:32:40.366Z'
---

## Overview

The WP Statistics  WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only on a nonce that every authenticated user holds, allowing users with Subscriber-level access and above to disclose the site's visitor analytics data.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
