CVE-2025-3953

WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin <= 14.13.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Update

The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'optionUpdater' function in all versions up to, and including, 14.13.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary plugin settings.


We have discovered 111,492 live websites that are affected by CVE-2025-3953.

Run a Free Instant Scan




Affected Software

Product  WP Statistics
Category Wordpress Plugins
Vulnerable Domains111,492 live websites (82.36% of WP Statistics install base)
Vulnerable Versions
  • from 0 through 14.13.3
Vulnerable Versions Count127 versions ( 98.45% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Apr 30, 2025
  • Updated - Apr 30, 2025

Credits

  • Trương Hữu Phúc (truonghuuphuc) (finder)

CVE-2025-3953 usage by Country

United States23,701 websites



Germany23,195 websites
France8,262 websites
Iran5,474 websites
Japan4,298 websites
Italy4,060 websites
Poland3,706 websites
Netherlands3,608 websites
GB2,625 websites
Denmark2,485 websites

CVE-2025-3953 usage by TLD

.com36,926 websites
.de14,178 websites
.org5,889 websites
.fr3,641 websites
.nl3,581 websites
.net3,234 websites
.it3,099 websites
.pl2,973 websites
.ch1,935 websites
.at1,673 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-3953

Top websites that are affected by CVE-2025-3953. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********************.org France***,***
*******.************.com United States***,***
*********.***.bg Bulgaria***,***
**********.ru Russia*,***,***
******.com United States*,***,***
*****.org United States*,***,***
**************.it Italy*,***,***
******.**.uk United States*,***,***
****************.org Germany*,***,***
******.com United States*,***,***
See full domain list

FAQ

CVE-2025-3953 is Missing Authorization in WP Statistics
A total of 111,492 websites have been identified as vulnerable to CVE-2025-3953, based on global website indexing conducted by WebTechSurvey.
The WP Statistics is affected by the CVE-2025-3953 vulnerability.
WP Statistics versions up to and including 14.13.3 are vulnerable to CVE-2025-3953.