Analytify <= 5.5.1 - Missing Authorization to Authenticated (Subscriber+) Minor Settings Update
medium
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rated() function in all versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with Subsc...
- CVSS:
- 4.3
- Affected:
- up to 5.5.1
- Fixed in:
- 6.0.0
- Disclosed:
- Mar 27, 2025
CVE-2025-30897 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 6.0.0
unknown
[en] Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.1.
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.0
- Disclosed:
- Mar 27, 2025
CVE-2025-30897 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.5.1
unknown
[en] Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.0.
- Affected:
- up to 5.5.1
- Fixed in:
- 5.5.1
- Disclosed:
- Feb 17, 2025
CVE-2025-26773 on NVD →
Analytify <= 5.5.0 - Missing Authorization
medium
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and a...
- CVSS:
- 4.3
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.1
- Disclosed:
- Feb 14, 2025
CVE-2025-26773 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.3.0
unknown
[en] Missing Authorization vulnerability in Analytify.This issue affects Analytify: from n/a through 4.2.3.
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
- Disclosed:
- Jan 2, 2025
CVE-2022-45830 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.1.1
unknown
[en] Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through 5.1.0.
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.1
- Disclosed:
- Dec 13, 2024
CVE-2023-41695 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.2.0
unknown
[en] Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through 5.1.1.
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.0
- Disclosed:
- Dec 9, 2024
CVE-2023-47841 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.5.0
unknown
[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Analytify.This issue affects Analytify: from n/a through 5.4.3.
- Affected:
- up to 5.5.0
- Fixed in:
- 5.5.0
- Disclosed:
- Dec 9, 2024
CVE-2024-53814 on NVD →
Analytify <= 5.4.3 - Missing Authorization
medium
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.4.3. This makes it possible for authenticated attackers, with Subscriber-level access and a...
- CVSS:
- 4.3
- Affected:
- up to 5.4.3
- Fixed in:
- 5.5.0
- Disclosed:
- Dec 2, 2024
CVE-2024-53814 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.4.0
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1.
- Affected:
- up to 5.4.0
- Fixed in:
- 5.4.0
- Disclosed:
- Aug 26, 2024
CVE-2024-43265 on NVD →
Analytify <= 5.3.1 - Cross-Site Request Forgery to Opt-out
medium
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3.1. This is due to missing or incorrect nonce validation on the optout_yes() function. This makes it possible for unauthenticated a...
- CVSS:
- 4.3
- Affected:
- up to 5.3.1
- Fixed in:
- 5.4.0
- Disclosed:
- Aug 12, 2024
CVE-2024-43265 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.2.4
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.2.3.
- Affected:
- up to 5.2.4
- Fixed in:
- 5.2.4
- Disclosed:
- Jun 8, 2024
CVE-2024-35689 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) <= 5.2.3 - Cross-Site Request Forgery
medium
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.3. This is due to missing or incorrect nonce validation on the wpa_check_authentication() function. This makes it possible for una...
- CVSS:
- 4.3
- Affected:
- up to 5.2.3
- Fixed in:
- 5.2.4
- Disclosed:
- Jun 6, 2024
CVE-2024-35689 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.2.4
unknown
[en] The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthentic...
- Affected:
- up to 5.2.4
- Fixed in:
- 5.2.4
- Disclosed:
- May 2, 2024
CVE-2024-1584 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.2.4
unknown
[en] The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for authenti...
- Affected:
- up to 5.2.4
- Fixed in:
- 5.2.4
- Disclosed:
- May 2, 2024
CVE-2024-1809 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) <= 5.2.3 - Missing Authorization
medium
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for authenticated...
- CVSS:
- 5.4
- Affected:
- up to 5.2.3
- Fixed in:
- 5.2.4
- Disclosed:
- Apr 29, 2024
CVE-2024-1809 on NVD →
Analytify <= 5.2.1 - Missing Authorization to Unauthenticated Google Analytics Tracking ID Modification
medium
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated...
- CVSS:
- 5.3
- Affected:
- up to 5.2.3
- Fixed in:
- 5.2.4
- Disclosed:
- Apr 26, 2024
CVE-2024-1584 on NVD →
Analytify Dashboard <= 5.1.1 - Cross-Site Request Forgery
medium
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the send_analytics_email function. This makes it possible for unauthent...
- CVSS:
- 4.3
- Affected:
- up to 5.1.1
- Fixed in:
- 5.2.0
- Disclosed:
- Nov 20, 2023
CVE-2023-47841 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.2.0
unknown
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the send_analytics_email function. This makes it possible for unauthent...
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.0
- Disclosed:
- Nov 20, 2023
Analytify Dashboard <= 5.1.0 - Missing Authorization to Opt-In
medium
The Analytify Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the optin_yes() function in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber-level and above access, to optin the the plugin's tra...
- CVSS:
- 4.3
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.1
- Disclosed:
- Sep 5, 2023
CVE-2023-41695 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.1.1
unknown
The Analytify Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the optin_yes() function in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber-level and above access, to optin the the plugin's tra...
- Affected:
- up to 5.1.1
- Fixed in:
- 5.1.1
- Disclosed:
- Sep 5, 2023
Analytify <= 4.2.3 - Missing Authorization & Cross-Site Request Forgery
medium
The Analytify plugin for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 4.2.3. This is due to missing nonce validation and a lack of capability checking on the logout() function. This makes it possible for unauthenticated attackers to invoke this function...
- CVSS:
- 4.3
- Affected:
- up to 4.2.3
- Fixed in:
- 4.3.0
- Disclosed:
- Jan 3, 2023
CVE-2022-45830 on NVD →
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.3.0
unknown
The Analytify plugin for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 4.2.3. This is due to missing nonce validation and a lack of capability checking on the logout() function. This makes it possible for unauthenticated attackers to invoke this function...
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
- Disclosed:
- Jan 3, 2023
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.2.3
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress.
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Nov 8, 2022
CVE-2022-38137 on NVD →
Analytify – Google Analytics Dashboard For WordPress <= 4.2.2 - Cross-Site Request Forgery
high
The Analytify – Google Analytics Dashboard For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.2. This is due to missing or incorrect nonce validation on the analytify_delete_cache action. This makes it possible for unauthenticated attackers to delete the...
- CVSS:
- 8.8
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.3
- Disclosed:
- Sep 29, 2022
CVE-2022-38137 on NVD →
Analytify – Google Analytics Dashboard For WordPress <= 4.2.2 - Authorization Bypass
medium
The Analytify plugin for WordPress is vulnerable to authorization bypass due to a missing capability and nonce checks on the analytify_delete_cache function in versions up to, and including, 4.2.2 . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the cache of t...
- CVSS:
- 6.5
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.3
- Disclosed:
- Aug 22, 2022
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.2.3
unknown
The Analytify plugin for WordPress is vulnerable to authorization bypass due to a missing capability and nonce checks on the analytify_delete_cache function in versions up to, and including, 4.2.2 . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the cache of t...
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.3
- Disclosed:
- Aug 22, 2022
Analytify <= 4.2.0 - Reflected Cross-Site Scripting
medium
The Analytify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.2.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 4.2.0
- Fixed in:
- 4.2.1
- Disclosed:
- Jun 20, 2022
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.2.1
unknown
The Analytify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.2.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.1
- Disclosed:
- Jun 20, 2022
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.2.1
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Analytify plugin (versions <= 4.2.0).
Update the WordPress Analytify plugin to the latest available version (at least 4.2.1).
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.1
- Disclosed:
- Jun 20, 2022
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.2.1
unknown
The plugin does not escape the current URL before outputting it back in a 404 page when the 404 tracking feature is enabled, leading to Reflected Cross-Site Scripting
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database