THREAT OPS › Threat News › [NVD] CVE-2026-5488 (MEDIUM 5.3) — The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi
[NVD] CVE-2026-5488 (MEDIUM 5.3) — The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi
CVE-2026-5488 CVSS: 5.3 MEDIUM Published: 2026-04-24T04:16:22.200
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is localized on all admin pages (includi
Indicators of compromise
- CVE-2026-5488cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-5488