Impact
The flaw is a missing capability check in the optionUpdater function of the WP Statistics plugin, which allows an authenticated user with Subscriber level access or higher to modify any plugin setting. This missing authorization (CWE-862) can alter tracking behavior, data collection, or privacy configurations, thereby compromising the intended privacy‑friendly functionality of the plugin and potentially exposing sensitive analytics data.
Affected Systems
Veronalabs’ WP Statistics – Simple, privacy‑friendly Google Analytics alternative is affected in all releases up to and including 14.13.3. Users running any of those versions on WordPress sites are vulnerable, regardless of custom configuration or theme.
Risk and Exploitability
The CVSS score of 5.4 classifies this vulnerability as medium severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. The likely attack vector requires an authenticated WordPress user with at least Subscriber privileges; an attacker must log in to a site, then exploit the exposed Ajax endpoint to change plugin settings. Without elevated system privileges or broader access, an attacker cannot trigger the flaw remotely.
OpenCVE Enrichment
EUVD