Unauthorized Plugin Installation in Google Analytics Dashboard for WordPress
CVE-2026-5464

7.2HIGH

What is CVE-2026-5464?

The ExactMetrics plugin for WordPress is susceptible to an exploitation that allows authenticated users with Editor-level access or higher to install and activate arbitrary plugins from external URLs. This vulnerability is caused by a flaw in the handling of the 'onboarding_key' transient, which is exposed on the reports page to users with the 'exactmetrics_view_dashboard' capability. The key serves as the only gate for a REST endpoint, enabling the retrieval of a one-time hash token, which is used for the installation process. Notably, the installation and activation processes lack adequate security checks, such as capability verification or nonce checks. As a result, attackers could leverage this vulnerability to introduce malicious code, resulting in Remote Code Execution (RCE) on the affected WordPress sites.

Affected Version(s)

ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) 0 <= 9.1.2

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ngoc Duc
.