CVE detail
CVE-2026-7444
The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. This makes it possible for unauthenticated attackers to delete arbitrary search-term records, including all associated search-history rows, via a forged request granted they can trick a user with access to the plugin's "Search Analytics" dashboard page (Administrator by default) into performing an action such as clicking on a link.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 11.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 8
- within the 30d window
- Peak daily
- 8
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d62b8380-1679-40d8-a77f-17c583e88d39?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comAug 5, 2026, 8:16 AM - https://wordpress.org/plugins/search-analytics/wordpress.org
No excerpt available.
Release Noteswordpress.orgAug 5, 2026, 8:16 AM - https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3525420%40search-analytics%2Ftrunk&old=3525419%40search-analytics%2Ftrunk&sfp_email=&sfph_mail=plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 5, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/search-analytics/trunk/admin/includes/class.stats-table.php#L132plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 5, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats.php#L99plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 5, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats-table.php#L132plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 5, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats-table.php#L125plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 5, 2026, 8:16 AM - https://plugins.trac.wordpress.org/browser/search-analytics/tags/1.4.16/admin/includes/class.stats-table.php#L112plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 5, 2026, 8:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-73423CVSS 5.1 · Medium
Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only through the middleware() primit…
- CVE-2026-48551CVSS 6.1 · Medium
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply mat…
- CVE-2026-73292CVSS 8.3 · High
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's sema…
- CVE-2026-47232CVSS 4.3 · Medium
Admidio is an open-source user management solution. Prior to version 5.0.10, the sensitive `mode=export` action in `modules/sso/keys.php` exports a PKCS#12 bundle containing the c…
- CVE-2026-47229CVSS 5.4 · Medium
Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm_csrf_token` on every state-changing branch except `enable`…
- CVE-2026-47228CVSS 5.2 · Medium
Admidio is an open-source user management solution. `modules/registration.php` mode `send_login` regenerates a random password for `user_uuid_assigned`, stores its bcrypt hash in…