PT-2026-24656 · Smub · Exactmetrics – Google Analytics Dashboard For Wordpress

Ali Sünbül

·

Publicado

2026-03-11

·

Atualizado

2026-03-15

·

CVE-2026-1993

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ExactMetrics – Google Analytics Dashboard for WordPress versions 7.1.0 through 9.0.2
Description The ExactMetrics – Google Analytics Dashboard for WordPress plugin exhibits an Improper Privilege Management issue. The update settings() function does not validate input, allowing authenticated attackers possessing the exactmetrics save settings capability to modify any plugin setting. Specifically, attackers can alter the save settings option, which governs user role access to plugin functionality. By modifying this setting to include the subscriber role, an attacker can grant administrative access to all subscribers on the site. The update settings() function is the component responsible for this behavior.
Recommendations Versions 7.1.0 through 9.0.2 are affected and should be updated when a fix is available. As a temporary workaround, restrict the exactmetrics save settings capability to only trusted users.

Correção

LPE

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-1993

Produtos afetados

Exactmetrics – Google Analytics Dashboard For Wordpress