Unauthorized Plugin Installation in Google Analytics Dashboard for WordPress
CVE-2026-5464
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 April 2026
What is CVE-2026-5464?
The ExactMetrics plugin for WordPress is susceptible to an exploitation that allows authenticated users with Editor-level access or higher to install and activate arbitrary plugins from external URLs. This vulnerability is caused by a flaw in the handling of the 'onboarding_key' transient, which is exposed on the reports page to users with the 'exactmetrics_view_dashboard' capability. The key serves as the only gate for a REST endpoint, enabling the retrieval of a one-time hash token, which is used for the installation process. Notably, the installation and activation processes lack adequate security checks, such as capability verification or nonce checks. As a result, attackers could leverage this vulnerability to introduce malicious code, resulting in Remote Code Execution (RCE) on the affected WordPress sites.
Affected Version(s)
ExactMetrics β Google Analytics Dashboard for WordPress (Website Stats Plugin) 0 <= 9.1.2