Vulnerabilidades conocidas, compatibilidad con PHP y alternativas más seguras para el plugin de WordPress Wp Analytify — verificado contra la base de datos de seguridad local de WP Clinic.
Qué hace este plugin
Estado de mantenimiento
Vulnerabilidades conocidas
11 CVEs conocidos registrados para Wp Analytify.
Reportadas entre 2022 y 2025.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2025-30897
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 6.0.0 |
Falta de control de autorización |
Media
4,3
|
< 6.0.0
|
6.0.0 |
2025-03-27 |
—
|
|
CVE-2025-26773
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.5.1 |
Falta de control de autorización |
Media
4,3
|
< 5.5.1
|
5.5.1 |
2025-02-14 |
—
|
|
CVE-2024-53814
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.5.0 |
Exposición de información sensible del sistema a una esfera de control no autorizada |
Media
6,5
|
< 5.5.0
|
5.5.0 |
2024-12-02 |
—
|
|
CVE-2024-43265
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.4.0 |
Falsificación de petición en sitios cruzados (CSRF) |
Baja
3,5
|
< 5.4.0
|
5.4.0 |
2024-08-12 |
—
|
|
CVE-2024-35689
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 |
Falsificación de petición en sitios cruzados (CSRF) |
Alta
8,8
|
< 5.2.4
|
5.2.4 |
2024-06-06 |
—
|
|
CVE-2024-1809
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 |
Exposición de información sensible del sistema a una esfera de control no autorizada |
Media
5,4
|
< 5.2.4
|
5.2.4 |
2024-04-29 |
—
|
|
CVE-2024-1584
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 |
Control de acceso incorrecto |
Media
5,3
|
< 5.2.4
|
5.2.4 |
2024-04-26 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.0 |
— |
Desconocido
|
< 5.2.0
|
5.2.0 |
2023-11-20 |
—
|
CVE-2025-30897
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the rated() function in all versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set the rated option to true.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-26773
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.5.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-53814
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.4.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-43265
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3.1. This is due to missing or incorrect nonce validation on the optout_yes() function. This makes it possible for unauthenticated attackers to opt out of tracking via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-35689
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.2.3. This is due to missing or incorrect nonce validation on the wpa_check_authentication() function. This makes it possible for unauthenticated attackers to update the Google Analytics tracking code via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-1809
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on AJAX functions in combination with nonce leakage in all versions up to, and including, 5.2.3. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain certain sensitive information related to plugin settings.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-1584
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated attackers to modify the site's Google Analytics tracking ID.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.0
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the send_analytics_email function. This makes it possible for unauthenticated attackers to send a feedback email usually sent on uninstall with admin consent via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
+ 10 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2023-47841
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.0 |
Falta de control de autorización |
Media
4,3
|
< 5.2.0
|
5.2.0 |
2023-11-20 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.1.1 |
— |
Desconocido
|
< 5.1.1
|
5.1.1 |
2023-09-05 |
—
|
|
CVE-2023-41695
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.1.1 |
Falta de control de autorización |
Baja
3,5
|
< 5.1.1
|
5.1.1 |
2023-09-05 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0 |
— |
Desconocido
|
< 4.3.0
|
4.3.0 |
2023-01-03 |
—
|
|
CVE-2022-45830
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0 |
Falta de control de autorización |
Media
6,5
|
< 4.3.0
|
4.3.0 |
2022-12-29 |
—
|
|
CVE-2022-38137
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3 |
Falsificación de petición en sitios cruzados (CSRF) |
Media
4,3
|
< 4.2.3
|
4.2.3 |
2022-09-29 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3 |
— |
Desconocido
|
< 4.2.3
|
4.2.3 |
2022-08-22 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 |
— |
Desconocido
|
< 4.2.1
|
4.2.1 |
2022-06-20 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 |
— |
Desconocido
|
< 4.2.1
|
4.2.1 |
2022-06-20 |
—
|
|
—
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1 |
— |
Desconocido
|
< 4.2.1
|
4.2.1 |
— |
—
|
CVE-2023-47841
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1.1. This is due to missing or incorrect nonce validation on the send_analytics_email function. This makes it possible for unauthenticated attackers to send a feedback email usually sent on uninstall with admin consent via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.1.1
The Analytify Dashboard plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the optin_yes() function in versions up to, and including, 5.1.0. This makes it possible for authenticated attackers, with subscriber-level and above access, to optin the the plugin's tracking.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-41695
Update the WordPress Analytify plugin to the latest available version (at least 5.1.1).
Abdi Pranata discovered and reported this Broken Access Control vulnerability in WordPress Analytify Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a function that could lead to an unprivileged user to executing a certain higher privileged action. This vulnerability has been fixed in version 5.1.1.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0
The Analytify plugin for WordPress is vulnerable to authorization bypass & Cross-Site Request Forgery in versions up to, and including, 4.2.3. This is due to missing nonce validation and a lack of capability checking on the logout() function. This makes it possible for unauthenticated attackers to invoke this function and log out an associated Google Analytics account either themself or via forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-45830
Update the WordPress Analytify plugin to the latest available version (at least 4.3.0).
Tien Nguyen Anh discovered and reported this Privilege Escalation vulnerability in WordPress Analytify Plugin. This could allow a malicious actor to escalate their low privileged account to something with higher privileges. After this they could take full control of the website. This vulnerability has been fixed in version 4.3.0.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2022-38137
The Analytify – Google Analytics Dashboard For WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.2.2. This is due to missing or incorrect nonce validation on the analytify_delete_cache action. This makes it possible for unauthenticated attackers to delete the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.3
The Analytify plugin for WordPress is vulnerable to authorization bypass due to a missing capability and nonce checks on the analytify_delete_cache function in versions up to, and including, 4.2.2 . This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete the cache of the plugin and also allows unauthenticated attackers to delete the plugin cache via forged request, granted they can trick a subscriber or higher into clicking on a link. Version 4.2.3 adds a nonce check to the function, which addressed the Cross-Site Request Forgery Vulnerability and makes exploitation impractical for lower-level accounts.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1
Reflected Cross-Site Scripting (XSS) vulnerability discovered by WPScanTeam in WordPress Analytify plugin (versions <= 4.2.0).
Update the WordPress Analytify plugin to the latest available version (at least 4.2.1).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1
The Analytify plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.2.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.2.1
The plugin does not escape the current URL before outputting it back in a 404 page when the 404 tracking feature is enabled, leading to Reflected Cross-Site Scripting
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Cómo solucionarlo
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.