The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'optionUpdater' function in all versions up to, and including, 14.13.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary plugin settings.
We have discovered 111,492 live websites that are affected by CVE-2025-3953.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 111,492 live websites (82.36% of WP Statistics install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 127 versions ( 98.45% of all versions) |
![]() | 23,701 websites |
![]() | 23,195 websites |
![]() | 8,262 websites |
![]() | 5,474 websites |
![]() | 4,298 websites |
![]() | 4,060 websites |
![]() | 3,706 websites |
![]() | 3,608 websites |
![]() | 2,625 websites |
![]() | 2,485 websites |
.com | 36,926 websites |
.de | 14,178 websites |
.org | 5,889 websites |
.fr | 3,641 websites |
.nl | 3,581 websites |
.net | 3,234 websites |
.it | 3,099 websites |
.pl | 2,973 websites |
.ch | 1,935 websites |
.at | 1,673 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********************.org | ![]() | ***,*** | |
*******.************.com | ![]() | ***,*** | |
*********.***.bg | ![]() | ***,*** | |
**********.ru | ![]() | *,***,*** | |
******.com | ![]() | *,***,*** | |
*****.org | ![]() | *,***,*** | |
**************.it | ![]() | *,***,*** | |
******.**.uk | ![]() | *,***,*** | |
****************.org | ![]() | *,***,*** | |
******.com | ![]() | *,***,*** |
FAQ