| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-5488 | ExactMetrics <= 9.1.2 - Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token' | smub | ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) | Medium | 5.3 | 2026-04-24 03:27:06 | Deep Dive |
| CVE-2026-5464 | ExactMetrics <= 9.1.2 - Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process | smub | ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) | High | 7.2 | 2026-04-23 08:28:26 | Deep Dive |
| CVE-2026-1992 | ExactMetrics 8.6.0 - 9.0.2 - Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation | smub | ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) | High | 8.8 | 2026-03-11 09:25:43 | Deep Dive |
| CVE-2026-1993 | ExactMetrics 7.1.0 - 9.0.2 - Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update | smub | ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) | High | 8.8 | 2026-03-11 09:25:42 | Deep Dive |
| CVE-2017-20092 | Google Analytics Dashboard Plugin cross site scriting | unspecified | Google Analytics Dashboard Plugin | Low | 3.5 | 2022-06-24 06:45:26 | Deep Dive |