plugin

Google Analyticator Vulnerabilities

10 known security issues reported for the Google Analyticator WordPress plugin. Most recent disclosed Jan 23, 2023.

3 high 2 medium

Running Google Analyticator on your site? Check whether your installed version is affected.

Scan your site free

Analyticator [google-analyticator] < 6.5.6 (closed)

unknown

[en] The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

Affected:
up to 6.5.6
Fixed in:
6.5.6
Disclosed:
Jan 23, 2023

CVE-2022-3425 on NVD →

Analyticator [google-analyticator] < 6.5.6 (closed)

unknown

[en] The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present

Affected:
up to 6.5.6
Fixed in:
6.5.6
Disclosed:
Jan 23, 2023

CVE-2022-4323 on NVD →

Google Analyticator <= 6.5.5 - Authenticated (Administrator+) PHP Object Injection

high

The Google Analyticator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5.5 via deserialization of untrusted input. This allows administrator-level attackers to inject a PHP Object. The additional presence of a POP chain in the vulnerable plugin may allow the attacker to d...

CVSS:
7.2
Affected:
up to 6.5.5
Fixed in:
6.5.6
Disclosed:
Jan 2, 2023

CVE-2022-4323 on NVD →

Google Analyticator <= 6.5.5 - Authenticated (Administrator+) PHP Object Injection

high

The Google Analyticator plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.5.5 via deserialization of untrusted input. This allows administrator-level attackers to inject a PHP Object. The additional presence of a POP chain in the vulnerable plugin may allow the attacker to...

CVSS:
7.2
Affected:
up to 6.5.5
Fixed in:
6.5.6
Disclosed:
Dec 27, 2022

CVE-2022-3425 on NVD →

Analyticator [google-analyticator] < 5.2.1 (closed)

unknown

[en] The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.

Affected:
up to 5.2.1
Fixed in:
5.2.1
Disclosed:
Aug 22, 2019

CVE-2009-5158 on NVD →

Analyticator [google-analyticator] < 6.4.9.4 (closed)

unknown

[en] Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563.

Affected:
up to 6.4.9.4
Fixed in:
6.4.9.4
Disclosed:
Sep 7, 2017

CVE-2015-4697 on NVD →

Analyticator [google-analyticator] < 6.4.9.6 (closed)

unknown

[en] Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3) ga_downloads_prefix, (4) ga_downloads, or (5) ga_outbound_prefix paramete...

Affected:
up to 6.4.9.6
Fixed in:
6.4.9.6
Disclosed:
Sep 21, 2015

CVE-2015-6238 on NVD →

Google Analyticator <= 6.4.9.5 - Cross-Site Scripting

medium

Multiple cross-site scripting (XSS) vulnerabilities in the Google Analyticator plugin before 6.4.9.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) ga_adsense, (2) ga_admin_disable_DimentionIndex, (3) ga_downloads_prefix, (4) ga_downloads, or (5) ga_outbound_prefix parameter in...

CVSS:
4.7
Affected:
up to 6.4.9.6
Fixed in:
6.4.9.6
Disclosed:
Aug 24, 2015

CVE-2015-6238 on NVD →

Google Analyticator <= 6.4.9.3 - Cross-Site Request Forgery

high

Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563.

CVSS:
8.8
Affected:
up to 6.4.9.4
Fixed in:
6.4.9.4
Disclosed:
Jun 19, 2015

CVE-2015-4697 on NVD →

Google Analyticator <= 5.2 - Cross-Site Scripting

medium

The google-analyticator plugin before 5.2.1 for WordPress has insufficient HTML sanitization for Google Analytics API text.

CVSS:
6.1
Affected:
up to 5.2.1
Fixed in:
5.2.1
Disclosed:
Jul 29, 2009

CVE-2009-5158 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database