plugin

Google Analytics For Wordpress Vulnerabilities

28 known security issues reported for the Google Analytics For Wordpress WordPress plugin. Most recent disclosed Jul 27, 2026.

3 high 7 medium 2 low

Running Google Analytics For Wordpress on your site? Check whether your installed version is affected.

Scan your site free

MonsterInsights <= 11.0.0 - Missing Authorization

medium

The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 11.0.0. This makes it possible for unauthenticated attackers to forge analytics data.

CVSS:
5.3
Affected:
up to 11.0.0
Fixed in:
11.1.0
Disclosed:
Jul 27, 2026

CVE-2026-11366 on NVD →

MonsterInsights <= 10.1.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure And Plugin Integration Reset

high

The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability checks on the get_ads_access_token() and reset_experience() functions in all versions up to, and including, 10.1.2. This...

CVSS:
7.1
Affected:
up to 10.1.2
Fixed in:
10.1.3
Disclosed:
May 12, 2026

CVE-2026-5371 on NVD →

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 8.22.0

unknown

[en] Missing Authorization vulnerability in MonsterInsights Google Analytics by Monster Insights.This issue affects Google Analytics by Monster Insights: from n/a through 8.21.0.

Affected:
up to 8.22.0
Fixed in:
8.22.0
Disclosed:
Apr 25, 2024

CVE-2023-52220 on NVD →

Google Analytics by Monster Insights <= 8.21.0 - Missing Authorization

medium

The Google Analytics by Monster Insights plugin for WordPress is vulnerable to unauthorized access due to a missing capability check in versions up to, and including, 8.21.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 8.21.0
Fixed in:
8.22.0
Disclosed:
Jan 5, 2024

CVE-2023-52220 on NVD →

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 8.14.1

unknown

[en] Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in MonsterInsights plugin <= 8.14.0 versions.

Affected:
up to 8.14.1
Fixed in:
8.14.1
Disclosed:
May 18, 2023

CVE-2023-23999 on NVD →

Google Analytics by Monster Insights <= 8.14.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The Google Analytics by Monster Insights plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.14.0 due to insufficient input sanitization and output escaping on the style attribute. This makes it possible for authenticated attackers, with contributor-level access and abo...

CVSS:
6.4
Affected:
up to 8.14.0
Fixed in:
8.14.1
Disclosed:
May 10, 2023

CVE-2023-23999 on NVD →

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 8.12.1

unknown

[en] The MonsterInsights WordPress plugin before 8.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

Affected:
up to 8.12.1
Fixed in:
8.12.1
Disclosed:
Feb 6, 2023

CVE-2023-0081 on NVD →

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 8.9.1

unknown

[en] The MonsterInsights WordPress plugin before 8.9.1 does not sanitize or escape page titles in the top posts/pages section, allowing an unauthenticated attacker to inject arbitrary web scripts into the titles by spoofing requests to google analytics.

Affected:
up to 8.9.1
Fixed in:
8.9.1
Disclosed:
Jan 16, 2023

CVE-2022-3904 on NVD →

MonsterInsights <= 8.12.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

medium

The MonsterInsights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via unspecified block options (used in pages and posts) in versions up to, and including, 8.12.0 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary we...

CVSS:
6.4
Affected:
up to 8.12.0
Fixed in:
8.12.1
Disclosed:
Jan 13, 2023

CVE-2023-0081 on NVD →

MonsterInsights <= 8.9.0 - Unauthenticated Stored Cross-Site Scripting via Google Analytics

medium

The MonsterInsights plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles and pages in versions up to, and including, 8.9.0 due to insufficient input sanitization and output escaping on those values. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in page...

CVSS:
5.4
Affected:
up to 8.9.0
Fixed in:
8.9.1
Disclosed:
Dec 23, 2022

CVE-2022-3904 on NVD →

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 7.2.0

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability found by RIPS Technologies in WordPress Google Analytics by Monster Insights plugin (versions <= 7.1.0).

Affected:
up to 7.2.0
Fixed in:
7.2.0
Disclosed:
Dec 7, 2018

MonsterInsights – Google Analytics Dashboard for WordPress <= 7.1 - Stored Cross-Site Scripting

medium

The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter in versions up to, and including 7.1. This makes it possible for lower-privileged attackers to inject arbitrary web scripts in administrative pages that execute whenever...

CVSS:
6.4
Affected:
up to 7.1
Fixed in:
7.2.0
Disclosed:
Sep 18, 2018

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 7.2.0

unknown

The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tab parameter in versions up to, and including 7.1. This makes it possible for lower-privileged attackers to inject arbitrary web scripts in administrative pages that execute whenever...

Affected:
up to 7.2.0
Fixed in:
7.2.0
Disclosed:
Sep 18, 2018

MonsterInsights - Google Analytics Dashboard for WordPress <= 5.4.4 - Authenticated Stored Cross-Site Scripting

low

The MonsterInsights - Google Analytics Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.4 due to insufficient privilege handling. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

CVSS:
3.8
Affected:
up to 5.4.4
Fixed in:
5.4.5
Disclosed:
Aug 10, 2015

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.4.5

unknown

The MonsterInsights - Google Analytics Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.4.4 due to insufficient privilege handling. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user...

Affected:
up to 5.4.5
Fixed in:
5.4.5
Disclosed:
Aug 10, 2015

MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) <= 5.3.3 - Cross-Site Scripting

high

The MonsterInsights – Google Analytics Dashboard for WordPress plugin is vulnerable to Cross-Site Scripting via the add_query_arg and remove_query_arg functions in versions up to, and including, 5.3.3. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
7.2
Affected:
up to 5.3.3
Fixed in:
5.4
Disclosed:
Apr 20, 2015

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.4

unknown

The MonsterInsights – Google Analytics Dashboard for WordPress plugin is vulnerable to Cross-Site Scripting via the add_query_arg and remove_query_arg functions in versions up to, and including, 5.3.3. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.

Affected:
up to 5.4
Fixed in:
5.4
Disclosed:
Apr 20, 2015

MonsterInsights – Google Analytics Dashboard for WordPress <= 5.3.2 - Stored Cross-Site Scripting

high

The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will exe...

CVSS:
7.2
Affected:
up to 5.3.2
Fixed in:
5.3.3
Disclosed:
Mar 19, 2015

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.3.3

unknown

The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will exe...

Affected:
up to 5.3.3
Fixed in:
5.3.3
Disclosed:
Mar 19, 2015

MonsterInsights – Google Analytics Dashboard for WordPress <= 5.3.2 - Authenticated Stored Cross-Site Scripting

medium

The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘manual_ua_code_field’ parameter in versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

CVSS:
5.5
Affected:
up to 5.3.2
Fixed in:
5.3.3
Disclosed:
Mar 6, 2015

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.3.3

unknown

The MonsterInsights – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘manual_ua_code_field’ parameter in versions up to, and including, 5.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers...

Affected:
up to 5.3.3
Fixed in:
5.3.3
Disclosed:
Mar 6, 2015

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.1.3

unknown

[en] Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Manually enter your UA code" (manual_ua_code_field) field in the General Settings.

Affected:
up to 5.1.3
Fixed in:
5.1.3
Disclosed:
Dec 2, 2014

CVE-2014-9174 on NVD →

MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) <= 5.1.2 - Cross-Site Scripting

low

Cross-site scripting (XSS) vulnerability in the Google Analytics by Yoast (google-analytics-for-wordpress) plugin before 5.1.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Manually enter your UA code" (manual_ua_code_field) field in the General Settings.

CVSS:
3.5
Affected:
up to 5.1.2
Fixed in:
5.1.3
Disclosed:
Nov 26, 2014

CVE-2014-9174 on NVD →

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 7.2.0

unknown

The Google Analytics Dashboard Plugin for WordPress by MonsterInsights WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 7.2.0
Fixed in:
7.2.0

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.4.5

unknown

The Google Analytics Dashboard Plugin for WordPress by MonsterInsights WordPress plugin was affected by an Authenticated Stored Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 5.4.5
Fixed in:
5.4.5

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.4

unknown

The Google Analytics Dashboard Plugin for WordPress by MonsterInsights WordPress plugin was affected by an Unauthenticated Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 5.4
Fixed in:
5.4

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.3.3

unknown

The Google Analytics Dashboard Plugin for WordPress by MonsterInsights WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 5.3.3
Fixed in:
5.3.3

MonsterInsights &#8211; Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.3.3

unknown

The Google Analytics Dashboard Plugin for WordPress by MonsterInsights WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.

Affected:
up to 5.3.3
Fixed in:
5.3.3

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database