CVE-2026-3570Disclosure

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing authentication and capability checks on the configuration reset functionality in the global scope of smarter-analytics.php. This makes it possible for unauthenticated attackers to reset all plugin configuration and delete all per-page/per-post analytics settings via the 'reset' parameter.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-21); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-31: 1PoC Mentioned / Linked · 2026-03-31: 1Exploit Tool / Code · 2026-03-31: 1Technical Details · 2026-03-21: 203-2103-31
Signal classification3 categories
Disclosure
133.3%
General
133.3%
PoC
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure1General1
2026-03-311
PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-3570-smarter-analytics-version-2-0-medium-vulnerability-proof-of-concept CVE-2026-3570 #WordPress plugin #vulnerability smarter-analytics https://atomicedge.io/?p=6569 #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsec…

    Post summary

    The post shares a proof‑of‑concept for CVE-2026-3570 affecting the Smarter Analytics WordPress plugin, but lacks details on active exploitation, patch, or technical specifics.

    0202058
    9 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3570 Unauthenticated Configuration Reset Vulnerability in Smarter Analytics WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3570

    Post summary

    A brief disclosure of CVE-2026-3570, an unauthenticated configuration reset vulnerability in Smarter Analytics WordPress Plugin, with no PoC, exploit, patch, or active exploitation mention.

    0000035
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3570 The Smarter Analytics plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0. This is due to missing authentication and cap… https://www.cve.org/CVERecord?id=CVE-2026-3570

    Post summary

    The CVE involves unauthorized access because of missing authentication, but no additional exploitation, patch, or PoC information is supplied.

    0000082
    56.8K followersView on X

Explore more