ExactMetrics <= 9.1.2 - Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token'
medium
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is localized on all admin p...
- CVSS:
- 5.3
- Affected:
- up to 9.1.2
- Fixed in:
- 9.1.3
- Disclosed:
- Apr 23, 2026
CVE-2026-5488 on NVD →
ExactMetrics <= 9.1.2 - Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process
high
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation in all versions up to, and including, 9.1.2. This is due to the reports page exposing the 'onboarding_key' transient to any user with the 'ex...
- CVSS:
- 7.2
- Affected:
- up to 9.1.2
- Fixed in:
- 9.1.3
- Disclosed:
- Apr 22, 2026
CVE-2026-5464 on NVD →
ExactMetrics - Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update vulnerability
critical
Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update vulnerability
- CVSS:
- 9.8
- Affected:
- up to 7.1.0-9.0.2
- Fixed in:
- 9.0.3
- Disclosed:
- Mar 12, 2026
ExactMetrics - Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation
high
Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation
- CVSS:
- 8.8
- Affected:
- up to 8.6.0-9.0.2
- Fixed in:
- 9.0.3
- Disclosed:
- Mar 12, 2026
ExactMetrics 7.1.0 - 9.0.2 - Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update
high
The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. This is due to the `update_settings()` function accepting arbitrary plugin setting names without a whitelist of allowed settings. This makes it possible for authenticated at...
- CVSS:
- 8.8
- Affected:
- 7.1.0 – 9.0.2
- Fixed in:
- 9.0.3
- Disclosed:
- Mar 10, 2026
CVE-2026-1993 on NVD →
ExactMetrics 8.6.0 - 9.0.2 - Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation
high
The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2. This is due to the `store_settings()` method in the `ExactMetrics_Onboarding` class accepting a user-supplied `triggered_by` parameter that is used instead of the current...
- CVSS:
- 8.8
- Affected:
- 8.0.0 – 9.0.2
- Fixed in:
- 9.0.3
- Disclosed:
- Mar 10, 2026
CVE-2026-1992 on NVD →
ExactMetrics <= 8.1.0 - Missing Authorization
medium
The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 8.1.0. This makes it possible for authenticated attackers, with Contributor-level access and...
- CVSS:
- 4.3
- Affected:
- up to 8.1.0
- Fixed in:
- 8.2.0
- Disclosed:
- Jan 24, 2025
CVE-2025-24750 on NVD →
ExactMetrics <= 7.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The ExactMetrics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...
- CVSS:
- 6.4
- Affected:
- up to 7.14.1
- Fixed in:
- 7.14.2
- Disclosed:
- May 9, 2023
CVE-2023-23880 on NVD →
ExactMetrics <= 7.12.0 - Authenticated (Contributor+) Cross-Site Scripting
medium
The ExactMetrics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified block options in posts/pages within versions up to, and including, 7.12.0 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts...
- CVSS:
- 6.4
- Affected:
- up to 7.12.0
- Fixed in:
- 7.12.1
- Disclosed:
- Jan 13, 2023
CVE-2023-0082 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database