CVE Explorer
CVE-2026-1992
The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2. This is due to the `store_settings()` method in the `ExactMetrics_Onboarding` class accepting a user-supplied `triggered_by` parameter that is used instead of the current user's ID to check permissions. This makes it possible for authenticated attackers with the `exactmetrics_save_settings` capability to bypass the `install_plugins` capability chec
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin)","vendor":"smub","versions":[{"lessThanOrEqual":"9.0.2","status":"affected","version":"8.0.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8dda3257224b26cf6a2e808b21d83f91918fd084c52dbb626231d7520dcb8405 · sha256:cddecb550f64b8ea… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":8.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8dda3257224b26cf6a2e808b21d83f91918fd084c52dbb626231d7520dcb8405 · sha256:cddecb550f64b8ea… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-639","description":"CWE-639 Authorization Bypass Through User-Controlled Key","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8dda3257224b26cf6a2e808b21d83f91918fd084c52dbb626231d7520dcb8405 · sha256:cddecb550f64b8ea… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"url":"https://plugins.trac.wordpress.org/browser/google-analytics-dashboard-for-wp/trunk/includes/admin/class-exactmetrics-onboarding.php#L273"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8dda3257224b26cf6a2e808b21d83f91918fd084c52dbb626231d7520dcb8405 · sha256:cddecb550f64b8ea… · /containers/cna/references/1
{"url":"https://plugins.trac.wordpress.org/changeset/3473805/google-analytics-dashboard-for-wp/trunk/includes/admin/class-exactmetrics-onboarding.php?old=3309894&old_path=google-analytics-dashboard-for-wp%2Ftrunk%2Fincludes%2Fadmin%2Fclass-exactmetrics-onboarding.php"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8dda3257224b26cf6a2e808b21d83f91918fd084c52dbb626231d7520dcb8405 · sha256:cddecb550f64b8ea… · /containers/cna/references/2
{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/79b6b896-df66-4c3d-a4d4-d3dbeb630134?source=cve"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8dda3257224b26cf6a2e808b21d83f91918fd084c52dbb626231d7520dcb8405 · sha256:cddecb550f64b8ea… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.