Analyticator [google-analyticator] < 6.5.6 (closed)
unknown
[en] The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
- Affected:
- up to 6.5.6
- Fixed in:
- 6.5.6
- Disclosed:
- Jan 23, 2023
CVE-2022-3425 on NVD →
Analyticator [google-analyticator] < 6.5.6 (closed)
unknown
[en] The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present
- Affected:
- up to 6.5.6
- Fixed in:
- 6.5.6
- Disclosed:
- Jan 23, 2023
CVE-2022-4323 on NVD →
Google Analyticator <= 6.5.5 - Authenticated (Administrator+) PHP Object Injection
high
The Google Analyticator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5.5 via deserialization of untrusted input. This allows administrator-level attackers to inject a PHP Object. The additional presence of a POP chain in the vulnerable plugin may allow the attacker to d...
- CVSS:
- 7.2
- Affected:
- up to 6.5.5
- Fixed in:
- 6.5.6
- Disclosed:
- Jan 2, 2023
CVE-2022-4323 on NVD →
Google Analyticator <= 6.5.5 - Authenticated (Administrator+) PHP Object Injection
high
The Google Analyticator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5.5 via deserialization of untrusted input. This allows administrator-level attackers to inject a PHP Object. The additional presence of a POP chain in the vulnerable plugin may allow the attacker to...
- CVSS:
- 7.2
- Affected:
- up to 6.5.5
- Fixed in:
- 6.5.6
- Disclosed:
- Dec 27, 2022
CVE-2022-3425 on NVD →
Analyticator [google-analyticator] < 5.2.1 (closed)
unknown
[en] The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.
- Affected:
- up to 5.2.1
- Fixed in:
- 5.2.1
- Disclosed:
- Aug 22, 2019
CVE-2009-5158 on NVD →
Analyticator [google-analyticator] < 6.4.9.4 (closed)
unknown
[en] Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563.
- Affected:
- up to 6.4.9.4
- Fixed in:
- 6.4.9.4
- Disclosed:
- Sep 7, 2017
CVE-2015-4697 on NVD →
Analyticator [google-analyticator] < 6.4.9.6 (closed)
unknown
[en] Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3) ga_downloads_prefix, (4) ga_downloads, or (5) ga_outbound_prefix paramete...
- Affected:
- up to 6.4.9.6
- Fixed in:
- 6.4.9.6
- Disclosed:
- Sep 21, 2015
CVE-2015-6238 on NVD →
Google Analyticator <= 6.4.9.5 - Cross-Site Scripting
medium
Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3) ga_downloads_prefix, (4) ga_downloads, or (5) ga_outbound_prefix parameter in...
- CVSS:
- 4.7
- Affected:
- up to 6.4.9.6
- Fixed in:
- 6.4.9.6
- Disclosed:
- Aug 24, 2015
CVE-2015-6238 on NVD →
Google Analyticator <= 6.4.9.3 - Cross-Site Request Forgery
high
Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563.
- CVSS:
- 8.8
- Affected:
- up to 6.4.9.4
- Fixed in:
- 6.4.9.4
- Disclosed:
- Jun 19, 2015
CVE-2015-4697 on NVD →
Google Analyticator <= 5.2 - Cross-Site Scripting
medium
The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.
- CVSS:
- 6.1
- Affected:
- up to 5.2.1
- Fixed in:
- 5.2.1
- Disclosed:
- Jul 29, 2009
CVE-2009-5158 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database