Wise Analytics <= 1.1.9 - Missing Authorization to Unauthenticated Arbitrary Analytics Database Disclosure via 'name' Parameter

2026-01-23 19:19
Lior Yeshayahu

Strategic Overview

Status
Patched in 1.1.20
Affected PluginWise Analytics
Affected Version<= 1.1.9
CVSS5.3Medium
CVECVE-2025-14609
View all Wise Analytics vulnerabilities

Vulnerability Overview

The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.9. This is due to missing capability checks on the REST API endpoint '/wise-analytics/v1/report'. This makes it possible for unauthenticated attackers to access sensitive analytics data including administrator usernames, login timestamps, visitor tracking information, and business intelligence data via the 'name' parameter granted they can send unauthenticated requests.

Technical Analysis

REMEDIATION: Update to version 1.1.20, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C