CVE-2025-3953

WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin <= 14.13.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Update

The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'optionUpdater' function in all versions up to, and including, 14.13.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary plugin settings.


We have discovered 54,422 live websites that are affected by CVE-2025-3953.

Run a Free Instant Scan




Affected Software

Product  WP Statistics
Category Wordpress Plugins
Vulnerable Domains54,422 live websites (45% of WP Statistics install base)
Vulnerable Versions
  • from 0 through 14.13.3
Vulnerable Versions Count118 versions ( 89% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Apr 30, 2025
  • Updated - Apr 8, 2026

Credits

  • Trương Hữu Phúc (truonghuuphuc) (finder)

Website Distribution by Country

Number of websites using CVE-2025-3953
United States8,386 websites



Germany10,338 websites
France4,233 websites
Iran3,118 websites
Italy2,297 websites
Poland2,140 websites
Japan2,014 websites
Netherlands1,772 websites
GB1,293 websites
Russia1,244 websites

Website Distribution by TLD

Number of websites using CVE-2025-3953
.com17,905 websites
.de6,583 websites
.org2,359 websites
.fr2,037 websites
.pl1,604 websites
.it1,583 websites
.net1,509 websites
.nl1,505 websites
.ru926 websites
.at886 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-3953

Top websites that are affected by CVE-2025-3953. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
****************.org United States**,***
*****.at Germany**,***
********.**********.com United States**,***
***********.fr France**,***
*****.*********.edu United States**,***
*******.com France**,***
****.org Australia**,***
*****.pl Poland**,***
****.it Italy**,***
See full domain list

FAQ

CVE-2025-3953 is Missing Authorization in WP Statistics
A total of 54,422 websites have been identified as vulnerable to CVE-2025-3953, based on global website indexing conducted by WebTechSurvey.
The WP Statistics is affected by the CVE-2025-3953 vulnerability.
WP Statistics versions up to and including 14.13.3 are vulnerable to CVE-2025-3953.