plugin

Wp Analytify Vulnerabilities

31 known security issues reported for the Wp Analytify WordPress plugin. Most recent disclosed Mar 27, 2025.

1 high 12 medium

Running Wp Analytify on your site? Check whether your installed version is affected.

Scan your site free

Analytify <= 5.5.1 - Missing Authorization to Authenticated (Subscriber+) Minor Settings Update

medium

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rated() function in all versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with Subsc...

CVSS:
4.3
Affected:
up to 5.5.1
Fixed in:
6.0.0
Disclosed:
Mar 27, 2025

CVE-2025-30897 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 6.0.0

unknown

[en] Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.1.

Affected:
up to 6.0.0
Fixed in:
6.0.0
Disclosed:
Mar 27, 2025

CVE-2025-30897 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.5.1

unknown

[en] Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.0.

Affected:
up to 5.5.1
Fixed in:
5.5.1
Disclosed:
Feb 17, 2025

CVE-2025-26773 on NVD →

Analytify <= 5.5.0 - Missing Authorization

medium

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and a...

CVSS:
4.3
Affected:
up to 5.5.0
Fixed in:
5.5.1
Disclosed:
Feb 14, 2025

CVE-2025-26773 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.3.0

unknown

[en] Missing Authorization vulnerability in Analytify.This issue affects Analytify: from n/a through 4.2.3.

Affected:
up to 4.3.0
Fixed in:
4.3.0
Disclosed:
Jan 2, 2025

CVE-2022-45830 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.1.1

unknown

[en] Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through 5.1.0.

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Dec 13, 2024

CVE-2023-41695 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.2.0

unknown

[en] Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through 5.1.1.

Affected:
up to 5.2.0
Fixed in:
5.2.0
Disclosed:
Dec 9, 2024

CVE-2023-47841 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.5.0

unknown

[en] Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Analytify.This issue affects Analytify: from n/a through 5.4.3.

Affected:
up to 5.5.0
Fixed in:
5.5.0
Disclosed:
Dec 9, 2024

CVE-2024-53814 on NVD →

Analytify <= 5.4.3 - Missing Authorization

medium

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.4.3. This makes it possible for authenticated attackers, with Subscriber-level access and a...

CVSS:
4.3
Affected:
up to 5.4.3
Fixed in:
5.5.0
Disclosed:
Dec 2, 2024

CVE-2024-53814 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.4.0

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.3.1.

Affected:
up to 5.4.0
Fixed in:
5.4.0
Disclosed:
Aug 26, 2024

CVE-2024-43265 on NVD →

Analytify <= 5.3.1 - Cross-Site Request Forgery to Opt-out

medium

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3.1. This is due to missing or incorrect nonce validation on the optout_yes() function. This makes it possible for unauthenticated a...

CVSS:
4.3
Affected:
up to 5.3.1
Fixed in:
5.4.0
Disclosed:
Aug 12, 2024

CVE-2024-43265 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.2.4

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Analytify.This issue affects Analytify: from n/a through 5.2.3.

Affected:
up to 5.2.4
Fixed in:
5.2.4
Disclosed:
Jun 8, 2024

CVE-2024-35689 on NVD →

Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) <= 5.2.3 - Cross-Site Request Forgery

medium

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.3. This is due to missing or incorrect nonce validation on the wpa_check_authentication() function. This makes it possible for una...

CVSS:
4.3
Affected:
up to 5.2.3
Fixed in:
5.2.4
Disclosed:
Jun 6, 2024

CVE-2024-35689 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.2.4

unknown

[en] The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthentic...

Affected:
up to 5.2.4
Fixed in:
5.2.4
Disclosed:
May 2, 2024

CVE-2024-1584 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.2.4

unknown

[en] The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for authenti...

Affected:
up to 5.2.4
Fixed in:
5.2.4
Disclosed:
May 2, 2024

CVE-2024-1809 on NVD →

Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) <= 5.2.3 - Missing Authorization

medium

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for authenticated...

CVSS:
5.4
Affected:
up to 5.2.3
Fixed in:
5.2.4
Disclosed:
Apr 29, 2024

CVE-2024-1809 on NVD →

Analytify <= 5.2.1 - Missing Authorization to Unauthenticated Google Analytics Tracking ID Modification

medium

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated...

CVSS:
5.3
Affected:
up to 5.2.3
Fixed in:
5.2.4
Disclosed:
Apr 26, 2024

CVE-2024-1584 on NVD →

Analytify Dashboard <= 5.1.1 - Cross-Site Request Forgery

medium

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the send_analytics_email function. This makes it possible for unauthent...

CVSS:
4.3
Affected:
up to 5.1.1
Fixed in:
5.2.0
Disclosed:
Nov 20, 2023

CVE-2023-47841 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.2.0

unknown

The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the send_analytics_email function. This makes it possible for unauthent...

Affected:
up to 5.2.0
Fixed in:
5.2.0
Disclosed:
Nov 20, 2023

Analytify Dashboard <= 5.1.0 - Missing Authorization to Opt-In

medium

The Analytify Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the optin_yes() function in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber-level and above access, to optin the the plugin's tra...

CVSS:
4.3
Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Sep 5, 2023

CVE-2023-41695 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 5.1.1

unknown

The Analytify Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the optin_yes() function in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber-level and above access, to optin the the plugin's tra...

Affected:
up to 5.1.1
Fixed in:
5.1.1
Disclosed:
Sep 5, 2023

Analytify <= 4.2.3 - Missing Authorization & Cross-Site Request Forgery

medium

The Analytify plugin for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 4.2.3. This is due to missing nonce validation and a lack of capability checking on the logout() function. This makes it possible for unauthenticated attackers to invoke this function...

CVSS:
4.3
Affected:
up to 4.2.3
Fixed in:
4.3.0
Disclosed:
Jan 3, 2023

CVE-2022-45830 on NVD →

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.3.0

unknown

The Analytify plugin for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 4.2.3. This is due to missing nonce validation and a lack of capability checking on the logout() function. This makes it possible for unauthenticated attackers to invoke this function...

Affected:
up to 4.3.0
Fixed in:
4.3.0
Disclosed:
Jan 3, 2023

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.2.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Analytify plugin <= 4.2.2 on WordPress.

Affected:
up to 4.2.3
Fixed in:
4.2.3
Disclosed:
Nov 8, 2022

CVE-2022-38137 on NVD →

Analytify – Google Analytics Dashboard For WordPress <= 4.2.2 - Cross-Site Request Forgery

high

The Analytify – Google Analytics Dashboard For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.2. This is due to missing or incorrect nonce validation on the analytify_delete_cache action. This makes it possible for unauthenticated attackers to delete the...

CVSS:
8.8
Affected:
up to 4.2.2
Fixed in:
4.2.3
Disclosed:
Sep 29, 2022

CVE-2022-38137 on NVD →

Analytify – Google Analytics Dashboard For WordPress <= 4.2.2 - Authorization Bypass

medium

The Analytify plugin for WordPress is vulnerable to authorization bypass due to a missing capability and nonce checks on the analytify_delete_cache function in versions up to, and including, 4.2.2 . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the cache of t...

CVSS:
6.5
Affected:
up to 4.2.2
Fixed in:
4.2.3
Disclosed:
Aug 22, 2022

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.2.3

unknown

The Analytify plugin for WordPress is vulnerable to authorization bypass due to a missing capability and nonce checks on the analytify_delete_cache function in versions up to, and including, 4.2.2 . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the cache of t...

Affected:
up to 4.2.3
Fixed in:
4.2.3
Disclosed:
Aug 22, 2022

Analytify <= 4.2.0 - Reflected Cross-Site Scripting

medium

The Analytify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.2.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

CVSS:
6.1
Affected:
up to 4.2.0
Fixed in:
4.2.1
Disclosed:
Jun 20, 2022

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.2.1

unknown

The Analytify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.2.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...

Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
Jun 20, 2022

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.2.1

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Analytify plugin (versions <= 4.2.0). Update the WordPress Analytify plugin to the latest available version (at least 4.2.1).

Affected:
up to 4.2.1
Fixed in:
4.2.1
Disclosed:
Jun 20, 2022

Analytify &#8211; Google Analytics Dashboard For WordPress (GA4 analytics made easy) [wp-analytify] < 4.2.1

unknown

The plugin does not escape the current URL before outputting it back in a 404 page when the 404 tracking feature is enabled, leading to Reflected Cross-Site Scripting

Affected:
up to 4.2.1
Fixed in:
4.2.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database