PT-2026-34850 · WordPress · Exactmetrics

Dmitry Ignatyev

·

Published

2026-04-24

·

Updated

2026-04-25

·

CVE-2026-5488

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ExactMetrics – Google Analytics Dashboard for WordPress versions prior to 9.1.3
Description Missing authorization in the plugin allows authenticated attackers with subscriber-level access or higher to retrieve valid Google Ads access tokens and reset Google Ads integration settings. This occurs because the AJAX handlers get ads access token() and reset experience() only verify the nonce and fail to perform necessary capability checks, unlike other endpoints in the same class that require the exactmetrics save settings capability.
Recommendations Update the plugin to a version later than 9.1.2. As a temporary workaround, restrict access to the get ads access token() and reset experience() AJAX handlers.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-5488

Affected Products

Exactmetrics