CVE Database /
CVE-2022-45830
CVE · Medium
CVE-2022-45830 — Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-45830
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 4.3.0 |
Missing Authorization |
Medium
6.5
|
< 4.3.0
|
4.3.0 |
2022-12-29 |
—
|
CVE-2022-45830
The Analytify plugin for WordPress before version 4.3.0 contains a flaw allowing unauthenticated attackers to disconnect Google Analytics accounts due to insufficient nonce verification and missing permission checks in the logout function. An attacker could exploit this by tricking an administrator into clicking a malicious link or by directly invoking the function to log out an associated Google Analytics account. The vulnerability enables both direct unauthorized logout actions and cross-site request forgery attacks against site administrators.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings