CVE-2026-1993 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: March 11, 2026
ExactMetrics Google Analytics Dashboard for WordPress - Broken Access Control
Overview
ExactMetrics ā Google Analytics Dashboard for WordPress plugin 7.1.0 through 9.0.2 contains an improper privilege management vulnerability caused by lack of whitelist in update_settings() function, letting authenticated attackers with exactmetrics_save_settings capability modify any plugin setting, including access control, exploit requires exactmetrics_save_settings capability.
Severity & Score
Impact
Authenticated attackers can escalate privileges by modifying plugin settings to grant administrative access to all subscribers.
Mitigation
Update to a version later than 9.0.2 or the latest available version.
References
- https://plugins.trac.wordpress.org/browser/google-analytics-dashboard-for-wp/trunk/includes/admin/routes.php#L201
- https://plugins.trac.wordpress.org/changeset/3473805/google-analytics-dashboard-for-wp/trunk/includes/admin/routes.php?old=3453934&old_path=google-analytics-dashboard-for-wp%2Ftrunk%2Fincludes%2Fadmin%2Froutes.php
- https://plugins.trac.wordpress.org/changeset/3473805/google-analytics-dashboard-for-wp/trunk/includes/capabilities.php?old=2897321&old_path=google-analytics-dashboard-for-wp%2Ftrunk%2Fincludes%2Fcapabilities.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/1c1ce474-ecce-4d21-b174-cb54a2441b2b?source=cve
- https://plugins.trac.wordpress.org/browser/google-analytics-dashboard-for-wp/tags/7.15.3/includes/admin/routes.php#L201
Social Media Activity(1 post)
š CVE-2026-1993 - High (8.8) The ExactMetrics ā Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. This is due to the `update_settings()` function accepting arbitrary plugin setting names without a... š https://www.thehackerwire.com/vulnerability/CVE-2026-1993/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-1993
- Severity
- High
- CVSS Score
- 8.8
- Type
- broken_access_control
- Status
- unconfirmed
- EPSS
- 4.2%
- Social Posts
- 1
CWE
- CWE-269
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H