{
 "id": "WPSEC-2026-0564",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0564/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0564/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0564/index.md",
 "title": "QA Assistants – Driven by data <= 5.3.0.0 - Authenticated (Subscriber+) Missing Authorization to Visitor Analytics Exposure and Heatmap/Replay Generation via Multiple AJAX Actions",
 "description": "The QA Assistants – Driven by data plugin for WordPress is vulnerable to unauthorized access due to missing capability and nonce checks on several AJAX actions (including ajax_get_realtime_list, ajax_get_session_num, ajax_init_heatmap_view, ajax_get_separate_data, ajax_create_heatmap_file, ajax_update_page_version, ajax_create_replay_file_to_raw_data and ajax_create_replay_file_to_data_base) in all versions up to, and including, 5.3.0.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view realtime visitor session data (pages visited, page titles, referrers, device, country and time on site) and heatmap data, and to trigger heatmap and replay file generation and page version refreshes, which make the server fetch recorded page URLs.",
 "plugin": {
  "slug": "qa-heatmap-analytics",
  "name": "QA Assistants – Driven by data",
  "full_name": "QA Assistants – Driven by data",
  "wordpress_org": "https://wordpress.org/plugins/qa-heatmap-analytics/",
  "advisories_url": "https://wpsec.com/vuln/plugin/qa-heatmap-analytics/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/qa-heatmap-analytics"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.4,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "5.3.0.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 5.3.0.1"
  ]
 },
 "introduced_in": null,
 "fixed_in": "5.3.0.1",
 "remediation": "Update to 5.3.0.1 or later.",
 "fix_released": "2026-10-05T09:18:13+00:00",
 "published": "2026-10-07T15:58:04+00:00",
 "updated": "2026-10-07T15:30:59.596297+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0564/",
  "https://plugins.svn.wordpress.org/qa-heatmap-analytics/tags/5.3.0.1/",
  "https://wordpress.org/plugins/qa-heatmap-analytics/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/qa-heatmap-analytics",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-07"
 }
}