{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-06T09:23:21.410","vulnerabilities":[{"cve":{"id":"CVE-2025-14609","sourceIdentifier":"security@wordfence.com","published":"2026-01-24T08:16:05.543","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"The Wise Analytics plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.1.9. This is due to missing capability checks on the REST API endpoint '/wise-analytics/v1/report'. This makes it possible for unauthenticated attackers to access sensitive analytics data including administrator usernames, login timestamps, visitor tracking information, and business intelligence data via the 'name' parameter granted they can send unauthenticated requests."},{"lang":"es","value":"El plugin Wise Analytics para WordPress es vulnerable a la falta de autorización en todas las versiones hasta la 1.1.9, inclusive. Esto se debe a la falta de comprobaciones de capacidad en el endpoint de la API REST '/wise-analytics/v1/report'. Esto permite que atacantes no autenticados accedan a datos analíticos sensibles, incluyendo nombres de usuario de administrador, marcas de tiempo de inicio de sesión, información de seguimiento de visitantes y datos de inteligencia de negocio, a través del parámetro 'name', siempre que puedan enviar solicitudes no autenticadas."}],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"weaknesses":[{"source":"security@wordfence.com","type":"Secondary","description":[{"lang":"en","value":"CWE-862"}]}],"references":[{"url":"https://plugins.trac.wordpress.org/browser/wise-analytics/tags/1.1.9/src/Endpoints/ReportsEndpoint.php#L43","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/wise-analytics/trunk/src/Endpoints/ReportsEndpoint.php#L43","source":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset/3446670/","source":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/d92c80cb-080b-4774-8c66-1d5cf68e771f?source=cve","source":"security@wordfence.com"}]}}]}