The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'optionUpdater' function in all versions up to, and including, 14.13.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary plugin settings.
We have discovered 54,422 live websites that are affected by CVE-2025-3953.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 54,422 live websites (45% of WP Statistics install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 118 versions ( 89% of all versions) |
| 8,386 websites | |
| 10,338 websites | |
| 4,233 websites | |
| 3,118 websites | |
| 2,297 websites | |
| 2,140 websites | |
| 2,014 websites | |
| 1,772 websites | |
| 1,293 websites | |
| 1,244 websites |
| .com | 17,905 websites |
| .de | 6,583 websites |
| .org | 2,359 websites |
| .fr | 2,037 websites |
| .pl | 1,604 websites |
| .it | 1,583 websites |
| .net | 1,509 websites |
| .nl | 1,505 websites |
| .ru | 926 websites |
| .at | 886 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ********.com | *,*** | ||
| ****************.org | **,*** | ||
| *****.at | **,*** | ||
| ********.**********.com | **,*** | ||
| ***********.fr | **,*** | ||
| *****.*********.edu | **,*** | ||
| *******.com | **,*** | ||
| ****.org | **,*** | ||
| *****.pl | **,*** | ||
| ****.it | **,*** |
FAQ