Impact
The WP Statistics WordPress plugin prior to version 14.16.10 fails to verify the user’s role when handling several AJAX requests that return visitor analytics. Because the only check is a nonce, any authenticated user—including Subscribers and higher—can invoke these endpoints and receive detailed analytics data about site visitors. This results in a breach of confidentiality where sensitive usage information is exposed to users that should not have access to it.
Affected Systems
Any instance of the WP Statistics plugin on a WordPress site running a version earlier than 14.16.10 is vulnerable. This includes all unsupported releases of the plugin, regardless of the WordPress core version.
Risk and Exploitability
The vulnerability requires a valid authenticated session with a Subscriber or higher role, which is commonly granted on WordPress sites. An attacker can simply call the exposed AJAX URLs to obtain analytics data without additional privileges. While this does not allow code execution or other forms of escalation, the disclosure of visitor information can be valuable for targeted phishing, privacy violations, or competitive intelligence. Current checks show the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate risk of exploitation but no known widespread use.
OpenCVE Enrichment