Impact
The vulnerability is a missing authorization flaw in the ExactMetrics plugin for WordPress. It allows an attacker to gain unauthorized access to the Google Analytics dashboard functionality that is normally restricted to privileged users. The weakness is a classic example of CWE-862 – Missing Authorization; it does not provide remote code execution but it permits reading analytics data that should be protected.
Affected Systems
Affected are sites running the Syed Balkhi ExactMetrics plugin, version 8.1.0 or earlier, for any WordPress installation. No specific WordPress core version constraints were listed in the advisory.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests that exploitation is currently considered unlikely. The vulnerability is not yet catalogued in the CISA KEV list. Based on the description, it is inferred that an attacker could exploit the plugin via its web interface to access restricted dashboard information, potentially as an authenticated or even unauthenticated user depending on site configuration.
OpenCVE Enrichment
EUVD