CVE · Medium

CVE-2020-20626 — Lara's Google Analytics (GA4) [lara-google-analytics] < 2.0.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-20626 Lara's Google Analytics (GA4) [lara-google-analytics] < 2.0.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 2.0.5 2.0.5 2019-10-14

CVE-2020-20626

Lara's Google Analytics plugin before version 2.0.5 contains a stored cross-site scripting flaw that allows authenticated attackers to inject malicious scripts into the application. The vulnerability was actively exploited in real-world attacks as documented by security research firm NinTechNet. Users running versions prior to 2.0.5 should upgrade immediately to address this issue.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.