Missing Authorization Vulnerability in ExactMetrics Google Analytics Dashboard for WordPress
CVE-2026-5488
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 April 2026
What is CVE-2026-5488?
The ExactMetrics Google Analytics Dashboard for WordPress plugin is vulnerable to missing authorization due to inadequate capability checks in certain AJAX handlers. Specifically, the functions get_ads_access_token() and reset_experience() fail to verify user permissions effectively, permitting authenticated users with subscriber-level access or higher to manipulate Google Ads settings and obtain access tokens. This vulnerability can lead to unauthorized changes in Google Ads configurations, posing a significant security threat to user accounts leveraging this plugin.
Affected Version(s)
ExactMetrics β Google Analytics Dashboard for WordPress (Website Stats Plugin) 0 <= 9.1.2