CVE Database /
CVE-2024-1809
CVE · Medium
CVE-2024-1809 — Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-1809
|
Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.2.4 |
Exposure of Sensitive System Information to an Unauthorized Control Sphere |
Medium
5.4
|
< 5.2.4
|
5.2.4 |
2024-04-29 |
—
|
CVE-2024-1809
The Analytify – Google Analytics Dashboard For WordPress plugin through version 5.2.3 contains a vulnerability stemming from inadequate permission validation in its AJAX handlers paired with exposed nonces. Authenticated users with subscriber-level permissions or greater can exploit this flaw to access restricted plugin configuration details. The issue arises from missing capability checks that fail to properly restrict who can invoke certain AJAX functions. This vulnerability affects all versions up to and including 5.2.3 and is patched in version 5.2.4.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings