References https://nvd.nist.gov/vuln/detail/CVE-2025-3953 https://wp-firewall.com/cve-2025-3953-wp-statistics-protect-your-wordpress-site-from-plugin-settings-exploit/ https://hackhalt.com/threat/cve-2025-3953/ https://cve.imfht.com/detail/CVE-2025-3953 https://patchstack.com/database/wordpress/plugin/wp-statistics/vulnerability/wordpress-wp-statistics-the-most-popular-privacy-friendly-analytics-plugin-plugin-14-13-3-missing-authorization-to-authenticated-subscriber-arbitrary-plugin-settings-update-vulnerability https://cve.ics-csirt.io/cve/CVE-2025-3953 https://vuldb.com/de/vuln/306581 https://wpscan.com/plugin/wp-statistics/
Related VulnerabilitiesPoCCVE-2026-81199: MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics DisclosurePoCCVE-2026-8181: WordPress Burst Statistics 3.4.0-3.4.1.1 - Authentication BypassWordPress Burst Statistics /wp-json/wp/v2/users/me 权限绕过漏洞(CVE-2026-8181)PoCwp-wpstatistics-log: WordPress Plugin WP Statistics Error Log DisclosurePoC索贝融媒体 /sobey-mchEditor/mch/Jzt/statistics/countJztArticleGroupByChannel2 SQL 注入漏洞索贝 /sobey-mchEditor/mch/statistics/countWxarticleByChannel SQL 注入漏洞索贝内容管理系统 /sobey-mchEditor/mch/statistics 多个SQL 注入漏洞PoCCVE-2021-24340: WordPress Statistics <13.0.8 - Blind SQL InjectionPoCCVE-2021-24750: WordPress Visitor Statistics (Real Time Traffic) <4.8 -SQL InjectionPoCCVE-2022-0651: WordPress Plugin WP Statistics <= 13.1.5 - SQL InjectionPoCCVE-2022-25148: WordPress Plugin WP Statistics <= 13.1.5 - SQL Injection