CVE · Medium

CVE-2024-1809 — Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-1809 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 Exposure of Sensitive System Information to an Unauthorized Control Sphere Medium 5.4 < 5.2.4 5.2.4 2024-04-29

CVE-2024-1809

The Analytify – Google Analytics Dashboard For WordPress plugin through version 5.2.3 contains a vulnerability stemming from inadequate permission validation in its AJAX handlers paired with exposed nonces. Authenticated users with subscriber-level permissions or greater can exploit this flaw to access restricted plugin configuration details. The issue arises from missing capability checks that fail to properly restrict who can invoke certain AJAX functions. This vulnerability affects all versions up to and including 5.2.3 and is patched in version 5.2.4.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.