CVE Database /
CVE-2014-9174
CVE
CVE-2014-9174 — MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.1.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2014-9174
|
MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 5.1.3 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Unknown
|
< 5.1.3
|
5.1.3 |
2014-11-26 |
—
|
CVE-2014-9174
The Google Analytics by Yoast plugin for WordPress prior to version 5.1.3 contains a cross-site scripting vulnerability in its General Settings page. Attackers can inject malicious scripts or HTML code through the "Manually enter your UA code" field, allowing them to execute arbitrary code in the context of affected websites. This flaw enables remote exploitation without requiring special privileges or user interaction beyond accessing the settings area.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings