CVE-2026-1993Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. This is due to the `update_settings()` function accepting arbitrary plugin setting names without a whitelist of allowed settings. This makes it possible for authenticated attackers with the `exactmetrics_save_settings` capability to modify any plugin setting, including the `save_settings` option that controls which user roles have access to plugin functionality. The admin intended to delegate configuration access to a trusted user, not enable that user to delegate access to everyone. By setting `save_settings` to include `subscriber`, an attacker can grant plugin administrative access to all subscribers on the site.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-03-11); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-11: 3Mentions · 2026-03-12: 1Mentions · 2026-03-15: 1Technical Details · 2026-03-11: 3Technical Details · 2026-03-15: 103-1103-1203-15
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-113
Disclosure3
2026-03-121
General1
2026-03-151
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-1993 The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. This is due to the `u… https://www.cve.org/CVERecord?id=CVE-2026-1993

    Post summary

    A new CVE for the ExactMetrics WordPress plugin is announced, detailing improper privilege management in specific versions, with no PoC, exploit, or patch information available.

    00000133
    56.7K followersView on X
  • RedPacket Security@RedPacketSec
    General

    CVE Alert: CVE-2026-1993 - smub - ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) - https://www.redpacketsecurity.com/cve-alert-cve-2026-1993-smub-exactmetrics-google-analytics-dashboard-for-wordpress-website-stats-plugin/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-1993 #smub #exactmetrics-google-analytics-dashboard-for-wordpress-website-stats-plugin

    Post summary

    The post issues a CVE alert for CVE‑2026‑1993 affecting the ExactMetrics WordPress plugin and directs readers to an external link for more information.

    0000075
    3.5K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1993 - High The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. This is due to the `update_settings()` func... https://www.thehackerwire.com/vulnerability/CVE-2026-1993/ https://t.co/POF4IbU1xG

    Post summary

    The tweet details a high‑severity vulnerability in ExactMetrics—specifying affected versions and a critical function—without mentioning a PoC, exploit, or patch.

    0000052
    134 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1993 Privilege Escalation in ExactMetrics WordPress Plugin via Unauthorized Settings Modification https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1993

    Post summary

    The CVE identifies a privilege escalation flaw in the ExactMetrics WordPress plugin that allows unauthorized modification of settings.

    000007
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1993: HIGH] ExactMetrics – Google Analytics Dashboard for WordPress plugin version 7.1.0 to 9.0.2 has an Improper Privilege Management vulnerability enabling attackers to modify plugin settings, incl...#cve,CVE-2026-1993,#cybersecurity https://cvefind.com/CVE-2026-1993

    Post summary

    The post announces that ExactMetrics plugin versions 7.1.0–9.0.2 are vulnerable to an Implicit Privilege Management flaw that lets attackers alter plugin settings; no PoC, exploit, or patch details are provided.

    0000039
    601 followersView on X

Explore more