
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3570 is a Missing Authorization vulnerability in the Smarter Analytics plugin for WordPress that allows unauthenticated attackers to reset all plugin configuration and delete per-page/per-post analytics settings. It affects all versions of the plugin up to and including version 2.0. The vulnerability was published on March 21, 2026, and was assigned by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, EUVD).
The root cause is a missing authentication and capability check (CWE-862: Missing Authorization) on the configuration reset functionality located in the global scope of smarter-analytics.php. Because the reset logic executes in the global scope without verifying the requester's identity or WordPress capabilities, any unauthenticated network request that includes the reset parameter can trigger the reset action. No special privileges, user interaction, or complex conditions are required for exploitation (Wordfence, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to wipe all Smarter Analytics plugin configuration and permanently delete per-page and per-post analytics tracking data. The primary impact is on data integrity and operational continuity of the analytics function; confidentiality and availability of the broader WordPress installation are not directly affected. While the vulnerability does not enable remote code execution or credential theft, repeated exploitation could disrupt analytics-dependent business processes and require manual reconfiguration (Wordfence).
No public exploit code or active in-the-wild exploitation campaigns have been reported for this vulnerability. The EPSS score is approximately 0.08%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and lack of authentication requirements make it trivially exploitable by any unauthenticated attacker who can reach the WordPress site (Wordfence).
reset parameter, targeting the endpoint where smarter-analytics.php is loaded in the global scope.GET https://target-site.com/wp-admin/admin-ajax.php?action=...&reset=1 or the equivalent direct file invocation, depending on how the plugin registers the hook.reset parameter targeting smarter-analytics.php endpoints, originating from unknown or automated IP addresses.reset=1 (or similar) parameter to plugin-related URLs from unauthenticated sessions (no valid session cookies).Update the Smarter Analytics plugin to version 2.1 or later, which introduces proper authentication and capability checks on the reset functionality. Site administrators unable to update immediately should consider deactivating the plugin until a patch can be applied. Additionally, restricting access to the WordPress admin and plugin files via web server rules (e.g., blocking direct PHP file access) can reduce the attack surface (Wordfence).
The vulnerability was reported and disclosed by Wordfence, a leading WordPress security firm, as part of their standard plugin vulnerability disclosure process. Coverage has been limited to automated vulnerability aggregation sites and security feeds, with no notable researcher commentary or significant community discussion identified beyond routine CVE tracking (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."