CVE · Medium

CVE-2023-23999 — MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 8.14.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-23999 MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) [google-analytics-for-wordpress] < 8.14.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 8.14.1 8.14.1 2023-05-10

CVE-2023-23999

The MonsterInsights Google Analytics plugin contained a cross-site scripting flaw that was discovered by Rafie Muhammad and reported through Patchstack. An attacker could exploit this vulnerability to inject harmful scripts into a website, including redirects, ads, or arbitrary HTML code that would execute for visitors. The issue has been resolved in version 8.14.1 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.