CVE · Low

CVE-2024-43265 — Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.4.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-43265 Analytify – Google Analytics Dashboard For WordPress (GA4 analytics tracking) [wp-analytify] < 5.4.0 Cross-Site Request Forgery (CSRF) Low 3.5 < 5.4.0 5.4.0 2024-08-12

CVE-2024-43265

The Analytify plugin for WordPress contains a Cross-Site Request Forgery vulnerability in versions up to 5.3.1 due to inadequate nonce verification in the optout_yes() function. An unauthenticated attacker could craft a malicious request that, if clicked by a site administrator, would disable tracking without authorization. The vulnerability was fixed in version 5.4.0.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.