# QA Assistants – Driven by data <= 5.3.0.0 - Authenticated (Subscriber+) Missing Authorization to Visitor Analytics Exposure and Heatmap/Replay Generation via Multiple AJAX Actions

- **ID:** WPSEC-2026-0564
- **Plugin:** QA Assistants – Driven by data (`qa-heatmap-analytics`), https://wordpress.org/plugins/qa-heatmap-analytics/
- **Affected versions:** all versions before 5.3.0.1
- **Fixed in:** 5.3.0.1 (Update to 5.3.0.1 or later.)
- **Severity:** Medium 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/qa-heatmap-analytics
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0564/

## Description

The QA Assistants – Driven by data plugin for WordPress is vulnerable to unauthorized access due to missing capability and nonce checks on several AJAX actions (including ajax_get_realtime_list, ajax_get_session_num, ajax_init_heatmap_view, ajax_get_separate_data, ajax_create_heatmap_file, ajax_update_page_version, ajax_create_replay_file_to_raw_data and ajax_create_replay_file_to_data_base) in all versions up to, and including, 5.3.0.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view realtime visitor session data (pages visited, page titles, referrers, device, country and time on site) and heatmap data, and to trigger heatmap and replay file generation and page version refreshes, which make the server fetch recorded page URLs.

## References

- https://wpsec.com/vuln/WPSEC-2026-0564/
- https://plugins.svn.wordpress.org/qa-heatmap-analytics/tags/5.3.0.1/
- https://wordpress.org/plugins/qa-heatmap-analytics/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0564/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
