# QA Assistants – Driven by data <= 5.3.0.0 - Unauthenticated Path Traversal to Limited File Overwrite via 'readers_name' and 'raw_name' Parameters

- **ID:** WPSEC-2026-0565
- **Plugin:** QA Assistants – Driven by data (`qa-heatmap-analytics`), https://wordpress.org/plugins/qa-heatmap-analytics/
- **Affected versions:** all versions before 5.3.0.1
- **Fixed in:** 5.3.0.1 (Update to 5.3.0.1 or later.)
- **Severity:** Critical 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H)
- **Weakness:** CWE-22
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/qa-heatmap-analytics
- **Fix released:** 2026-10-05
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0565/

## Description

The QA Assistants – Driven by data plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.3.0.0. This is due to the public tracking endpoint building file paths from client-supplied values without validation. This makes it possible for unauthenticated attackers to overwrite existing PHP files that the web server can write to with plugin session data, which can take the site offline, and to create files outside the plugin's data directory. The written data is not executed as code.

## References

- https://wpsec.com/vuln/WPSEC-2026-0565/
- https://plugins.svn.wordpress.org/qa-heatmap-analytics/tags/5.3.0.1/
- https://wordpress.org/plugins/qa-heatmap-analytics/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0565/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
