CVE · Medium

CVE-2022-45830 — Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-45830 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0 Missing Authorization Medium 6.5 < 4.3.0 4.3.0 2022-12-29

CVE-2022-45830

The Analytify plugin for WordPress before version 4.3.0 contains a flaw allowing unauthenticated attackers to disconnect Google Analytics accounts due to insufficient nonce verification and missing permission checks in the logout function. An attacker could exploit this by tricking an administrator into clicking a malicious link or by directly invoking the function to log out an associated Google Analytics account. The vulnerability enables both direct unauthorized logout actions and cross-site request forgery attacks against site administrators.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.