CVE-2026-1992Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2. This is due to the `store_settings()` method in the `ExactMetrics_Onboarding` class accepting a user-supplied `triggered_by` parameter that is used instead of the current user's ID to check permissions. This makes it possible for authenticated attackers with the `exactmetrics_save_settings` capability to bypass the `install_plugins` capability check by specifying an administrator's user ID in the `triggered_by` parameter, allowing them to install arbitrary plugins and achieve Remote Code Execution. This vulnerability only affects sites on which administrator has given other user types the permission to view reports and can only be exploited by users of that type.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-11); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-11: 2Mentions · 2026-03-12: 1Mentions · 2026-03-15: 1Technical Details · 2026-03-11: 2Technical Details · 2026-03-15: 103-1103-1203-15
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-112
Disclosure2
2026-03-121
Disclosure1
2026-03-151
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-1992 The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2. This is due to the… https://www.cve.org/CVERecord?id=CVE-2026-1992

    Post summary

    CVE-2026-1992 reports an Insecure Direct Object Reference in ExactMetrics plugin versions 8.6.0‑9.0.2; no PoC, exploit, patch, or active exploitation is referenced.

    00000141
    56.7K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-1992 - smub - ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) - https://www.redpacketsecurity.com/cve-alert-cve-2026-1992-smub-exactmetrics-google-analytics-dashboard-for-wordpress-website-stats-plugin/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-1992 #smub #exactmetrics-google-analytics-dashboard-for-wordpress-website-stats-plugin

    Post summary

    A security alert announces CVE-2026-1992 affecting the ExactMetrics WordPress plugin, directing readers to a link for further details, but provides no technical specifics or proof-of-concept evidence.

    0000075
    3.5K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1992 - High The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2. This is due to the `store_settings()` me... https://www.thehackerwire.com/vulnerability/CVE-2026-1992/ https://t.co/skY1RR3MGR

    Post summary

    The post announces a high‑severity IDOR vulnerability in ExactMetrics WordPress plugin versions 8.6.0 through 9.0.2, without providing PoC, exploit code, or patch information.

    0000043
    134 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1992: HIGH] Vulnerability in ExactMetrics - Google Analytics Dashboard for WordPress plugin versions 8.6.0 - 9.0.2 allows RCE. Attackers bypass permissions to install plugins.#cve,CVE-2026-1992,#cybersecurity https://cvefind.com/CVE-2026-1992

    Post summary

    The tweet announces a high‑severity RCE vulnerability (CVE‑2026‑1992) in ExactMetrics plugin for WordPress, affecting versions 8.6.0‑9.0.2, which allows attackers to bypass plugin installation permissions.

    0000044
    601 followersView on X

Explore more