plugin

Host Analyticsjs Local Vulnerabilities

2 known security issues reported for the Host Analyticsjs Local WordPress plugin. Most recent disclosed Dec 12, 2023.

2 medium

Running Host Analyticsjs Local on your site? Check whether your installed version is affected.

Scan your site free

CAOS | Host Google Analytics Locally <= 4.7.14 - Missing Authorization to Unauthenticated Plugin Settings Update

medium

The CAOS | Host Google Analytics Locally plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'update_settings' function in versions up to, and including, 4.7.14. This makes it possible for unauthenticated attackers to update plugin settings.

CVSS:
6.5
Affected:
up to 4.7.14
Fixed in:
4.7.15
Disclosed:
Dec 12, 2023

CVE-2023-6637 on NVD →

CAOS <= 4.1.8 - Admin+ Arbitrary Folder Deletion via Path Traversal

medium

The CAOS | Host Google Analytics Locally WordPress plugin before 4.1.9 does not validate the cache directory setting, allowing high privilege users to use a path traversal vector and delete arbitrary folders when uninstalling the plugin

CVSS:
4.9
Affected:
up to 4.1.8
Fixed in:
4.1.9
Disclosed:
Dec 1, 2021

CVE-2021-25020 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database