plugin

Google Analytics Dashboard For Wp Vulnerabilities

9 known security issues reported for the Google Analytics Dashboard For Wp WordPress plugin. Most recent disclosed Apr 23, 2026.

1 critical 4 high 4 medium

Running Google Analytics Dashboard For Wp on your site? Check whether your installed version is affected.

Scan your site free

ExactMetrics <= 9.1.2 - Authenticated (Subscriber+) Missing Authorization to Google Ads Access Token Retrieval via AJAX Action 'exactmetrics_ads_get_token'

medium

The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is localized on all admin p...

CVSS:
5.3
Affected:
up to 9.1.2
Fixed in:
9.1.3
Disclosed:
Apr 23, 2026

CVE-2026-5488 on NVD →

ExactMetrics <= 9.1.2 - Authenticated (Editor+) Arbitrary Plugin Installation/Activation via exactmetrics_connect_process

high

The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation and activation in all versions up to, and including, 9.1.2. This is due to the reports page exposing the 'onboarding_key' transient to any user with the 'ex...

CVSS:
7.2
Affected:
up to 9.1.2
Fixed in:
9.1.3
Disclosed:
Apr 22, 2026

CVE-2026-5464 on NVD →

ExactMetrics - Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update vulnerability

critical

Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update vulnerability

CVSS:
9.8
Affected:
up to 7.1.0-9.0.2
Fixed in:
9.0.3
Disclosed:
Mar 12, 2026

ExactMetrics - Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation

high

Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation

CVSS:
8.8
Affected:
up to 8.6.0-9.0.2
Fixed in:
9.0.3
Disclosed:
Mar 12, 2026

ExactMetrics 7.1.0 - 9.0.2 - Authenticated (Custom) Improper Privilege Management to Role Privilege Escalation via Settings Update

high

The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Improper Privilege Management in versions 7.1.0 through 9.0.2. This is due to the `update_settings()` function accepting arbitrary plugin setting names without a whitelist of allowed settings. This makes it possible for authenticated at...

CVSS:
8.8
Affected:
7.1.0 – 9.0.2
Fixed in:
9.0.3
Disclosed:
Mar 10, 2026

CVE-2026-1993 on NVD →

ExactMetrics 8.6.0 - 9.0.2 - Authenticated (Custom) Insecure Direct Object Reference to Arbitrary Plugin Installation

high

The ExactMetrics – Google Analytics Dashboard for WordPress plugin is vulnerable to Insecure Direct Object Reference in versions 8.6.0 through 9.0.2. This is due to the `store_settings()` method in the `ExactMetrics_Onboarding` class accepting a user-supplied `triggered_by` parameter that is used instead of the current...

CVSS:
8.8
Affected:
8.0.0 – 9.0.2
Fixed in:
9.0.3
Disclosed:
Mar 10, 2026

CVE-2026-1992 on NVD →

ExactMetrics <= 8.1.0 - Missing Authorization

medium

The ExactMetrics – Google Analytics Dashboard for WordPress (Website Stats Plugin) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 8.1.0. This makes it possible for authenticated attackers, with Contributor-level access and...

CVSS:
4.3
Affected:
up to 8.1.0
Fixed in:
8.2.0
Disclosed:
Jan 24, 2025

CVE-2025-24750 on NVD →

ExactMetrics <= 7.14.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The ExactMetrics plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 7.14.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages th...

CVSS:
6.4
Affected:
up to 7.14.1
Fixed in:
7.14.2
Disclosed:
May 9, 2023

CVE-2023-23880 on NVD →

ExactMetrics <= 7.12.0 - Authenticated (Contributor+) Cross-Site Scripting

medium

The ExactMetrics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified block options in posts/pages within versions up to, and including, 7.12.0 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts...

CVSS:
6.4
Affected:
up to 7.12.0
Fixed in:
7.12.1
Disclosed:
Jan 13, 2023

CVE-2023-0082 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database