Missing Authorization Vulnerability in ExactMetrics Google Analytics Dashboard for WordPress
CVE-2026-5488

5.3MEDIUM

What is CVE-2026-5488?

The ExactMetrics Google Analytics Dashboard for WordPress plugin is vulnerable to missing authorization due to inadequate capability checks in certain AJAX handlers. Specifically, the functions get_ads_access_token() and reset_experience() fail to verify user permissions effectively, permitting authenticated users with subscriber-level access or higher to manipulate Google Ads settings and obtain access tokens. This vulnerability can lead to unauthorized changes in Google Ads configurations, posing a significant security threat to user accounts leveraging this plugin.

Affected Version(s)

ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) 0 <= 9.1.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dmitrii Ignatyev
.