CVE · Medium

CVE-2024-1584 — Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1584 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 Improper Access Control Medium 5.3 < 5.2.4 5.2.4 2024-04-26

CVE-2024-1584

The Analytify plugin for WordPress through version 5.2.1 contains a flaw in the 'wpa_check_authentication' function where proper capability verification is absent, allowing unauthenticated users to alter the Google Analytics tracking ID assigned to a website. This vulnerability permits unauthorized modification of critical analytics configuration data without requiring valid user credentials.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.